VPN Authentication & Mapping Issue

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hello All
I have already posted this in another group but don't seem to be getting a
hit and I am getting some what desperate for a solution.

I have a very strange problem that I am hoping sure someone here is able to
help me solve.
Our setup is like this:
1. Windows 2003 domain
2. Many remote users with IBM laptops or Fujisu Stylistic Tablets
3. Checkpoint SecureClient VPN client software
4. RSA Ace server for VPN authentication
5. Scriptlogic 6.5.2 for mapping drives etc

The problem:
We have several users that authenticate to our network through a VPN
connection. These users have Checkpoint SecureClient installed on their
machines and are authenticated to a RSA Ace server that is a Member Server
in our domain. Once the user is logged on they run a batch file that maps
thier network drives via a short-cut to the Slogic.bat file in the Netlogon
directory of our PDC Emulator. Now for most people this is not a problem but
for some laptop
users and all Fujisu Tablet users the process of trying to run the login
script takes anywhere from 30-60 minutes to complete. What happens to the
people having a problem is this:
1. User runs the short-cut to Slogic.bat
2. After about 7-15 minutes they are prompted for a username and password
3. If they type in their domain user name and password they get prompted
again after about 4-10 more minutes with a message saying "that
authentication has been previously tried and failed".
4. The user can then type in a username and password from a temporary
account I created to help resolve this problem. This account is just a
simple domain user.
5. After several more minutes the logon screen will appear but can take up
to 35-40 to complete
6. When complete, the user checks for their drives but none have mapped.

As you can image, they are not very happy after taking all of this time only
to find out things did not work.

If the same user logs onto the network with the same machine while they are
in the office, everything works very quickly and as it should.

I have looked in the trace file that Scriptlogic creates and this an example
of the error message that I see:
08:44:58 Mapping drive G \\Server1\Graphics [SLP00001 1/30]
08:46:02 Error: Unable to map drive: 1265 The system detected a possible
attempt to compromise security. Please ensure that you can contact the server
that authenticated you.
OR
20:52:27 Error: Unable to map drive: 1326 Logon failure: unknown user name
or bad password.

I have been in contact with Scriptlogic and they tell me it is a Windows
authentication issue. I read one post where a person appeared to have a
somewhat similar issue to mine and they apparently resolved it by hard coding
the DNS address to on the user machine to point to the DNS server in the
domain. I gave this a shot but did not have any success. This seems to be
an obvious case of authentication but for the life of me I am stumped.

Hopefully someone out there has run into the same problem that has been
dogging me for several months and is able to lend a hand.

Thank you to all that take the time to read this and especially those that
fire me off some suggestions.

JD Benton



.



Relevant Pages

  • Please help with Remote Access Problem!
    ... machines and are authenticated to a RSA Ace server that is a Member Server ... thier network drives via a short-cut to the Slogic.bat file in the Netlogon ... script takes anywhere from 30-60 minutes to complete. ... authentication has been previously tried and failed". ...
    (microsoft.public.win2000.security)
  • RE: Wireless Security Notes and Findings (from this list and other places)
    ... There are two general areas of wireless security: Authentication and ... authentication standard that works with wireless networks. ... client computer runs a client program to connect to the network with a ...
    (Security-Basics)
  • Re: ADSI Problem
    ... Right I've got the script working now with my ASP applications by passing the ... If you are doing forms authentication using ADSI (which it sounds like you ... Restarting IIS usually gets it working again. ... Dim strUserName ...
    (microsoft.public.windows.server.active_directory)
  • Re: IP address assignment problem
    ... I have a little problem and seek for ur thoughts, let's assume I'm in a very open environment where everyone can very easily try to get his/her laptop on the network and IP addresses are assigned by a DHCP server and we are in a domain environment, how do I prevent machines that are not part of our domain to be assigned an IP address? ... This approach doesn't stop your rogue clients from connecting to other clients, but merely doesn't give them the information they normally need to do so. ... Using 802.1x, your workstations authenticate through the switch to a radius server before they are allowed any connectivity. ... This authentication can use X.509 certificates, computer account credentials from AD, or whatever else you'd normally configure radius to authenticate with. ...
    (Focus-Microsoft)
  • Re: Kerberos machine authentication - apparent authentication failures
    ... When you joined your computer to the domain your wireless network card was ... denied access until you can authenticate to a domain controller as a user. ... While kerberos is the default authentication protocol of choice, ...
    (microsoft.public.windows.server.security)