Routers
Problem for Routers
Generic problem for all Routers

Ipsec passthru problems connection ok but...




By gvnwht on Dec 19, 2008

" "
I have a problemwith a Nortel VPN client that cannot authenticate to windows/kerberos servers however can access other resources within the network which do not require (kerberos) authentication. The problem seems to relate directly to a particular router model (so far) - Belkin N1 MIMO. We have contacted Belkin who have suggested a firware upgrade (to 3.01.06) - this was applied but did not rectify the issue, have since downgraded to 3.01.04 as the 06 version was prerelease. The ISP have been contacted but the fault happens on different ISP connections. All test have been performed via a wired connection, however same problem does apply when using the wireless adapter.
From Users Home network - Belkin N1 MIMO (model number: F5D8631-4) / ISP1
User can login to VPN
User CAN get to Internet via company proxy
User CAN get to Internal web applications after entering username password
User CAN NOT get to Outlook, and Network Shares
From separate test ADSL Internet connection - Netcomm ADSL 2 Router / ISP2
User can login to VPN
Everything normal
Connected Belkin router to test ADSL connection / ISP - Bigpond.com
User can login to VPN
User CAN get to Internet via company proxy
User CAN get to Internal web applications after entering username password
User CAN NOT get to Outlook, and Network Shares
I have tracked the issue to some event log entries on the client computer attached as follows:
Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40961
Description: The Security System could not establish a secured connection with the server exchangeMDB/xyz.corp.com. No authentication protocol was available.
Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40960
Description: The Security System detected an attempted downgrade attack for server exchangeMDB/xyz.corp.com. The failure code from authentication protocol Kerberos was ''There are currently no logon servers available to service the logon request.
(0xc000005e)''.
In my troubleshooting I have encountered mention of KB885887 which is a kerberos hotfix (http://support.microsoft.com/kb/885887/en-us), and a registry key (http://www.eventid.net/display.asp?eventid=40960&eventno=787&source=LsaSrv&phase=1) forcing Kerberos to use TCP rather than UDP - to avoid UDP fragmentation issues. I have tried both options and this HAS NOT improved the situation either. I have tried lowering the MTU values (1300 seemed to be a sweetspot) but this has not proved to be an adequate fix, just delaying the fault/issue for a while..

I have also tried the following on the Belkin router:
disable Firewall
placed host as DMZ host on Router
disabled UPNP
Wireshark captures directly before and after a Lock/Unlock of the workstation appear to show a failure in the Kerberos authentication process when the VPN is connected through this router, however the vpn tunnel is seemingly ok..

The simple answer would be to throw out the router and use a compatable one, but since this is a common and popular router brand it is feasable that there will be more issues of this type - it would be nice to have a solution if and when that happens.

Popular Solutions for Routers


Questions and Unsolved Problems for Routers


Answer
We have a 3000 sq ft split level house, so range is critical (could we extend range with antennas,... (More)

Answer
turning on wireless on my stepnote laptop

Answer
How do I redo password on my encore router cause now i cant connect it with my iphone because i... (More)

Answer
How can I get a key code FOR MY ROUTER DLINK 108G MIMO

Answer
I have a compaq laptop and a wireless adapter that has been connected to the wireless network but I... (More)


Didn't find what you were looking for?

Describe your problem:

Select a Category:







Ask our Experts

 

Solve Your Problem Now!
Chat Live with an Expert
Chat Now
Browse popular Problems
More Common Problems
Most Common Problems for:
For Routers:

Top Router Experts

Rank: Guru Guru  

Solutions: 3663
Member Since: June 2007

Experience: Semi retired, was network administrator, proficient with hardware, software, networks, CAD systems

Ask Me
Find more Router Experts

Top Computer & Laptop Repair

(877) 934-6198
Send your laptop to us and we will diagnose the...
A+ Rated Oceanside Computer Sales & Service, LLC

(952) 890-7770
Zkarlo.com provides discount and used laptop parts...
Zkarlo.com


       
Solve Your Problem Now!
Chat Live with an Expert
Chat Now

X
Continue
When the original poster rates a solution that was given to his own problem, that rating is locked!
X

Are you sure the solution content is Inappropriate?
   
Tech buddies can communicate directly to answer questions. Become a Tech Buddy and have direct access to your favorite expert for FREE!
Insert Link
Insert Image
Insert You-Tube clip
Insert List
Insert List
Spell Check

What is this?



Select