Windows Built-In VPN Client Issues

Has anyone seen this before, and if so, what is the cure?

Action needed, but no system prompt, no DUO prompt.

Ultimately times out. I am curious as to why there is a request for action, but no push and no next steps.

I can add a basic framework of my setup for reference.
Configuration Elements

  • Peplink Balance One Core edge router
  • Server 2012 R2 Domain Controller with NAP
  • Server 2019 VPN Server with RRAS + NAP + DUO Proxy
  • DUO config - I have tried several approaches Radius client, AD client, both, etc.
  • I have ports 443 open in/out on all relevant devices
  • Test device: Windows 10, Built-In VPN client

UPDATE: I figured it out. If you also are trying to do this, I will post a walk-thru.

While I do not need this (yet), Iā€™m sure many, including myself, would love it if you could post your solution. Thank you, @shedev.

1 Like

I can tell you that the NPS plays a role, on both the RRAS server and a domain controller. The setup is simple, but not straightforward. I will post more at a later date.

Currently, we installed DUO on the RRAS server and using Active Directory to authenticate. and it is giving me this error

ā€œ The connection was prevented because of a policy configured on your RAS/VPN server. Specifically, the authentication method used by the server to verify your username and password may not match the authentication method configured in your connection profile. Please contact the Administrator of the RAS server and notify them of this error.ā€