Re: RAS errors - removing Everyone from Pre-Windows 2000

From: Sharoon Shetty K [MSFT] (sharoons_at_online.microsoft.com)
Date: 07/26/04


Date: Mon, 26 Jul 2004 18:54:25 +0530

Generally the error 930 is caused in the following cases:
1. When your RADIUS server is not reachable from your VPN server.
2. This issue may occur if the computer account has permissions to read the
Active Directory directory service record, but it does not have permissions
to write to the Active Directory record.

To verify the user permissions in the Active Directory Users and Computers
snap-in on a Windows 2000 domain controller. To do this, follow these steps:
  1.. Click Start, point to Programs, point to Administrative Tools, and
then click Active Directory Users and Computers.
  2.. Expand your domain.
  3.. Right-click Domain Controllers, and then click Properties.
  4.. Click the Group Policy tab, click Default Domain Controllers Policy,
and then click Edit.
  5.. Expand Computer Configuration, expand Windows Settings, expand
Security Settings, expand Local Policies, and then click User Rights
Assignment.
  6.. Double-click Access this computer from the network.
  7.. By default, the Administrators, the Authenticated Users, and the
Everyone groups are assigned this user right. If these groups are not
assigned this user right, add them. To do so, click Add, locate the user or
group you want to add, and then click OK two times.

-- 
Thanks,
Sharoon
---------------------------------------------------------
This posting is provided "AS IS" with no warranties, and confers no rights.
"Ras is Up" <anonymous@discussions.microsoft.com> wrote in message
news:40c601c4730e$af156d90$a401280a@phx.gbl...
> Hello Support,
> We have a 2k domain running in native mode with a modem
> pool configured on a 2k server running RRAS with a policy
> setup to allow a certain gropu to vpn in.  When i remove
> the everyone group from "Pre-Windows 2000 compatible
> access" group, VPN and dialin authentification fails with
> error 930.  How can i fix this security hole?
>
>


Relevant Pages

  • Re: VPN error 930
    ... When your RADIUS server is not reachable from your VPN server. ... This issue may occur if the computer account has permissions to read the Active Directory directory service record, but it does not have permissions to write to the Active Directory record. ... Expand your domain. ... Click the Group Policy tab, click Default Domain Controllers Policy, and then click Edit. ...
    (microsoft.public.win2000.ras_routing)
  • Re: VPN Problem - Error 930 and Event 20073
    ... This issue may occur if the computer account has permissions to read ... the Active Directory directory service record, ... Expand your domain. ... Click the Group Policy tab, click Default Domain Controllers Policy, ...
    (microsoft.public.win2000.ras_routing)
  • Re: Why do i need to know AD ?
    ... DNS Support for Active Directory Technical Reference ... Is the directory service included in the Windows Server 2000/2003 family. ... controller to interact with domain controllers in the domain running Windows ... used to configure replication between sites. ...
    (microsoft.public.windows.server.active_directory)
  • Re: gracefully removing a child domain
    ... run ADMT to create active user accounts in Active Directory. ... Windows Server 2003 Tools ... How to Upgrade Windows 2000 Domain Controllers to Windows Server 2003 ... ensure that you have designed a DNS and Active ...
    (microsoft.public.windows.server.active_directory)
  • Re: One way AD replication problem
    ... both domain controllers. ... Used ldap to look at the GC through port 3269. ... Set the primarydc to be a global catalog server again. ... Using active directory Users and computers I deleted the computer ...
    (microsoft.public.windows.server.active_directory)