Re: IAS error 49

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



I was not able to get this working on the original server. Switched to a
different dc and it works perfectly now.

"barberless" wrote:

Yes, I saw this post and restored the ias.mdb and recreated everything, but
didn't see any difference in the policy options. I also uninstalled IAS,
re-copied the ias.mdb, restarted, reinstalled and the policy list was already
populated with the policy I created previously. Perhaps I misunderstood the
instructions in the post. After copying the ias.mdb file, what should the
next step have been?

Thanks for responding.

"Robert L (MS-MVP)" wrote:

Is it possible you deleted the default Connection Request Policies policy
when you created the policy? This post may help,

IAS Reason-Code = 49
http://www.chicagotech.net/netforums/viewtopic.php?p=2854#2854
--
Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on
http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on
http://www.HowToNetworking.com


"barberless" <barberless@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:8C8936AA-4675-4452-9148-A6ED847BAA2C@xxxxxxxxxxxxxxxx
Attempting to setup IAS so that a Watchguard firewall can authenticate
PPTP
connections. Following Watchguard instructions and MS instructions
installed
IAS on a Win2003 Server, SP2, domain controller. Registered the server
with
Active Directory. There is one policy which says to grant access to the
windows group pptp_users. The pptp_user group is populated with users who
have dial-in access rights in their profile and we're using reversible
encryption at the domain level. Here is the error I receive when trying
to
connect. Any ideas on how to solve this is appreciated.

User xxxxx was denied access.
Fully-Qualified-User-Name = <undetermined>
NAS-IP-Address = 127.0.0.1
NAS-Identifier = <not present>
Called-Station-Identifier = <not present>
Calling-Station-Identifier = <not present>
Client-Friendly-Name = Firebox
Client-IP-Address = 65.181.48.59
NAS-Port-Type = <not present>
NAS-Port = 0
Proxy-Policy-Name = <none>
Authentication-Provider = <undetermined>
Authentication-Server = <undetermined>
Policy-Name = <undetermined>
Authentication-Type = <undetermined>
EAP-Type = <undetermined>
Reason-Code = 49
Reason = The connection attempt did not match any connection request
policy.




.



Relevant Pages

  • Re: 802.1x authentication for wireless issues w/ ISA 2004
    ... Access Policy, ... But I still wonder why it stops working if you stop IAS from ... IAS server in "New features for IAS" Can't remember how I got forwarded ... In the "connection request policies" The default policy there is fine but ...
    (microsoft.public.windows.server.sbs)
  • Re: How to allow users to create groups and shares
    ... Add the user/group to the Computer configuration, windows settings, security settings, Local policies, "Allow logon locally" in the Default domain controllers policy and on a existing or new created policy for the member servers. ... Filtering: Not Applied ... check with GPMC on the server or from a client the policy settings. ...
    (microsoft.public.windows.server.active_directory)
  • Domain Controller Security Policy errors
    ... Security Policy or the Domain Controller Security Policy. ... The DC is also a print and file server. ... The domain controller for Group Policy operations is not available. ...
    (microsoft.public.win2000.active_directory)
  • RE: Cant set Local Security policies. They fail to save
    ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
    (microsoft.public.windows.server.sbs)
  • Re: Move W2K3 server to its own OU seperate from SBS (MyBusiness) OU
    ... OU and move the member server to so that it does not inherit it's GPO from ... policies from inheriting the default domain policies of the SBS ... section of the default domain policy. ... In direct answer to your question, you would need to filter this ...
    (microsoft.public.windows.server.sbs)