Apple Event: May 7th at 7 am PT

Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

VPN - Authentication Failed

Hey there everyone. I'm having a little bit of a time with VPN services right now. Every time I try and connect to my server I receive the error message "Authentication failed." I get the error with both L2TP and PPTP.

I thought it might have been firewall port issues, but the vpn server logs show that I'm at least hitting the server. And to boot, I've also tried to connect through the local network.

I've tried connecting with both protocols on both a Tiger (10.4.11) client and a Leopard (10.5.1) client. I'm really lost here. This is what the last log said:

2007-12-11 17:03:44 PST Incoming call... Address given to client = 192.168.1.166
Tue Dec 11 17:03:44 2007 : Directory Services Authentication plugin initialized
Tue Dec 11 17:03:44 2007 : Directory Services Authorization plugin initialized
Tue Dec 11 17:03:44 2007 : L2TP incoming call in progress
Tue Dec 11 17:03:44 2007 : L2TP received SCCRQ
Tue Dec 11 17:03:44 2007 : L2TP sent SCCRP
Tue Dec 11 17:03:44 2007 : L2TP received SCCCN
Tue Dec 11 17:03:44 2007 : L2TP received ICRQ
Tue Dec 11 17:03:44 2007 : L2TP sent ICRP
Tue Dec 11 17:03:44 2007 : L2TP received ICCN
Tue Dec 11 17:03:44 2007 : L2TP connection established.
Tue Dec 11 17:03:44 2007 : using link 0
Tue Dec 11 17:03:44 2007 : Using interface ppp0
Tue Dec 11 17:03:44 2007 : Connect: ppp0 <--> socket[34:18]
Tue Dec 11 17:03:44 2007 : sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0xd33fb7f5> <pcomp> <accomp>]
Tue Dec 11 17:03:44 2007 : rcvd [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0xe133dae6> <pcomp> <accomp>]
Tue Dec 11 17:03:44 2007 : lcp_reqci: returning CONFACK.
Tue Dec 11 17:03:44 2007 : sent [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0xe133dae6> <pcomp> <accomp>]
Tue Dec 11 17:03:44 2007 : rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0xd33fb7f5> <pcomp> <accomp>]
Tue Dec 11 17:03:44 2007 : sent [LCP EchoReq id=0x0 magic=0xd33fb7f5]
Tue Dec 11 17:03:44 2007 : sent [CHAP Challenge id=0x19 <76680e5497407cf0af0c6648e73f5832>, name = "macserver.example.net"]
Tue Dec 11 17:03:44 2007 : rcvd [LCP EchoReq id=0x0 magic=0xe133dae6]
Tue Dec 11 17:03:44 2007 : sent [LCP EchoRep id=0x0 magic=0xd33fb7f5]
Tue Dec 11 17:03:44 2007 : rcvd [LCP EchoRep id=0x0 magic=0xe133dae6]
Tue Dec 11 17:03:44 2007 : rcvd [CHAP Response id=0x19 <94477a9cf92a11a5f1ef15caaae323010000000000000000e623c53fa21b252f9e34b8c564fcc7 3b0b7aa258f43bc95d00>, name = "vpnuser"]
Tue Dec 11 17:03:44 2007 : Peer vpnuser failed CHAP authentication
Tue Dec 11 17:03:44 2007 : sent [CHAP Failure id=0x19 "\37777777677\37777777777\37777777772\020"]
Tue Dec 11 17:03:44 2007 : sent [LCP TermReq id=0x2 "Authentication failed"]
Tue Dec 11 17:03:44 2007 : rcvd [LCP TermReq id=0x2 "Failed to authenticate ourselves to peer"]
Tue Dec 11 17:03:44 2007 : sent [LCP TermAck id=0x2]
Tue Dec 11 17:03:44 2007 : rcvd [LCP TermAck id=0x2]
Tue Dec 11 17:03:44 2007 : Connection terminated.
Tue Dec 11 17:03:44 2007 : L2TP disconnecting...
Tue Dec 11 17:03:44 2007 : L2TP sent CDN
Tue Dec 11 17:03:44 2007 : L2TP sent StopCCN
Tue Dec 11 17:03:44 2007 : L2TP disconnected
2007-12-11 17:03:44 PST --> Client with address = 192.168.1.166 has hungup

I've read the tutorial on MacLive.net( http://www.maclive.net/sid/132), and my setup is almost the same. I also tried the steps mentioned here:

http://docs.info.apple.com/article.html?artnum=107915

Is there maybe a checkbox somewhere that I may have missed? Do I need to enable users the right to VPN? Any help is greatly appreciated, and I would be more than happy to give out info to test. Thanks.

-Fish

XServe G5, Mac OS X (10.4.10), MacBook Pro

Posted on Dec 11, 2007 5:14 PM

Reply
Question marked as Best reply

Posted on Dec 12, 2007 3:28 PM

Nevermind. I found out what was wrong.

For anyone out there who cares to know: When you input the username for the connection settings, make sure you put in the user's shortname, not any of the shortname aliases. For example, if the user's real name is John Smith, the Workgroup Manager will usually make the first shortname for you as johnsmith. So use that, NOT jsmith, j.smith, or supersmith. I hope this can save someone 2 days in the future. I wish it would have for me. Thanks.
2 replies
Question marked as Best reply

Dec 12, 2007 3:28 PM in response to fishtenors

Nevermind. I found out what was wrong.

For anyone out there who cares to know: When you input the username for the connection settings, make sure you put in the user's shortname, not any of the shortname aliases. For example, if the user's real name is John Smith, the Workgroup Manager will usually make the first shortname for you as johnsmith. So use that, NOT jsmith, j.smith, or supersmith. I hope this can save someone 2 days in the future. I wish it would have for me. Thanks.

VPN - Authentication Failed

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.