Connect to VPN:Error 691

I have connected to before VPN with no errors but suddenly I get error 691 and I can't solve it. I have try several (.pbk) VPN connection. What should I do?

I have connected to before VPN with no errors but suddenly I get error 691 and I can't solve it. I have try several (.pbk) VPN connection. What should I do?

See these possible help...

http://www.howtonetworking.com/vpnissues/error691.htm

http://www.chicagotech.NET/NetForums/viewtopic.php?t=235

.. .or post on the appropriate Windows Server forum...

http://social.technet.Microsoft.com/forums/en/category/WindowsServer

MS - MVP Windows Expert - consumer
"When all else fails try what the captain suggested before you started...". »

Tags: Windows

Similar Questions

  • I have windows vista Enterprise edition and trying to connect to a PPTP VPN, I get an error 691.

    I have windows vista Enterprise edition and trying to connect to a PPTP VPN, I get an error 691 name of user and password are fine, I can connect to the VPN on XP without problem.

    original title: VPN Error 691

    I was able to find a solution by the way that the domain has been configured. I was adding the complete domain name and extension (i.e. domain.local). The .local was me screwing up. I edited the domain field to only reflect the domain name without any extensions. One that I did this it worked like a charm. I have been using a VPN PPTP on a computer Server 2003 domain mixed with 2000 and 2003 domain controllers and Windows 7 Pro laptop computers. Hope this helps someone.

  • VPN with AD authentication fails Error 691

    Hello

    I have configured my asa 5510 use AD for authentication of the vpn users.  Although I am using l2tp ipsec I used the following document as a line manager https://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00808c3c45.shtml#prereq

    .  When testing within the ASDM AD connection is successful.

    .  When you try to connect with a microsoft vpn client I get error 691: the remote connection was denied because the user name and password combination, you have provided is not recognized or the selected authentication protocol is not permitted on the remote access server.  On the vpn client, I have only active MSCHAPv2 and I require encryption.

    .  When debugging ldap 255 running I get the following output

    [26] starting a session
    [26] new application Session, framework 0xd8760198, reqType = authentication
    [26] the fiber began
    [26] Failed: the user name or password is empty
    [26] output fiber Tx = 0 bytes Rx = 0 bytes, status =-3
    [26] end of session

    Before you configure my conncetion VPN profile to use AD, I was able to connect using the LOCAL users.  When connected to the vpn, there is no access to the network.

    Here is the output of conf, see the

    name of host host1
    Select r2.d52YOdvbTM6/l encrypted password
    2KFQnbNIdI.2KYOU encrypted passwd
    names of
    !
    interface Ethernet0/0
    nameif outside
    security-level 0
    IP 100.100.100.178 255.255.255.240 watch 100.100.100.179
    !
    interface Ethernet0/1
    nameif Inside_1
    security-level 60
    IP 20.20.20.2 255.255.255.0 watch 20.20.20.3
    !
    interface Ethernet0/2
    nameif Inside_2
    security-level 90
    IP 30.30.30.2 255.255.255.0 watch 30.30.30.3
    !
    interface Ethernet0/3
    nameif DMZ
    security-level 30
    IP 10.10.3.2 255.255.255.0 watch 10.10.3.3
    !
    interface Management0/0
    Failover LAN Interface Description
    !
    passive FTP mode
    clock timezone THATS 1
    clock to summer time CEDT recurring last Sun Mar 02:00 last Sun Oct 03:00
    Standard access list DefaultRAGroup_splitTunnelAcl allow 20.20.20.0 255.255.255.0
    20.20.20.0 IP Access-list extended sheep 255.255.255.0 allow 10.0.5.0 255.255.255.0
    pager lines 24
    asdm of logging of information
    Outside 1500 MTU
    MTU 1500 Inside_1
    MTU 1500 Inside_2
    MTU 1500 DMZ
    IP local pool clientVPNpool 10.0.5.10 - 10.0.5.150 mask 255.255.255.0
    failover
    secondary failover lan unit
    failover lan interface failoverlink Management0/0
    failover interface ip failoverlink 90.0.0.2 255.255.255.0 ensures 90.0.0.3
    ICMP unreachable rate-limit 1 burst-size 1
    don't allow no asdm history
    ARP timeout 14400
    Global (1 interface external)
    NAT 0 access-list sheep (Inside_1)
    NAT (Inside_1) 1 0.0.0.0 0.0.0.0
    Route outside 0.0.0.0 0.0.0.0 100.100.100.177 1
    Timeout xlate 03:00
    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    dynamic-access-policy-registration DfltAccessPolicy
    AAA-server ActiveDirectory ldap Protocol
    AAA-Server Active Directory (Inside_1) 20.20.20.24
    LDAP-base-dn OU = ouname, DC = domain_name, DC = local
    LDAP-scope subtree
    LDAP-naming-attribute sAMAccountName
    LDAP-login-password *.
    LDAP-connection-dn CN = cisco, OU = Service accounts, OR = ouname, DC = domain_name, DC = local
    microsoft server type
    the ssh LOCAL console AAA authentication
    Enable http server
    http 20.20.20.0 255.255.255.0 Inside_1
    http 30.30.30.0 255.255.255.0 Inside_2
    No snmp server location
    No snmp Server contact
    Server enable SNMP traps snmp authentication linkup, linkdown cold start
    Crypto ipsec transform-set esp-3des esp-sha-hmac TRANS_ESP_3DES_SHA
    Crypto ipsec transform-set transit mode TRANS_ESP_3DES_SHA
    Crypto ipsec transform-set ESP-AES-256-MD5 esp-aes-256 esp-md5-hmac
    Crypto ipsec transform-set ESP-DES-SHA esp - esp-sha-hmac
    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac
    Crypto ipsec transform-set ESP-DES-MD5 esp - esp-md5-hmac
    Crypto ipsec transform-set ESP-AES-192-MD5 esp-aes-192 esp-md5-hmac
    Crypto ipsec transform-set ESP-3DES-MD5-esp-3des esp-md5-hmac
    Crypto ipsec transform-set ESP-AES-256-SHA 256 - aes - esp esp-sha-hmac
    Crypto ipsec transform-set transport mode ESP-AES-256-SHA
    Crypto ipsec transform-set ESP-AES-128-SHA aes - esp esp-sha-hmac
    Crypto ipsec transform-set ESP-AES-128-SHA mode transit
    Crypto ipsec transform-set ESP-AES-192-SHA esp-aes-192 esp-sha-hmac
    Crypto ipsec transform-set ESP-AES-128-MD5-esp - aes esp-md5-hmac
    life crypto ipsec security association seconds 28800
    Crypto ipsec kilobytes of life - safety 4608000 association
    Crypto dynamic-map SYSTEM_DEFAULT_CRYPTO_MAP 65535 value transform-set ESP-AES-128-SHA ESP-AES-128-MD5 ESP-AES-192-SHA ESP-AES-192-MD5 ESP-AES-256-SHA ESP-AES-256-MD5 ESP-3DES-SHA MD5-ESP-3DES ESP-DES-SHA ESP-DES-MD5 TRANS_ESP_3DES_SHA
    card crypto Outside_map 65535-isakmp dynamic ipsec SYSTEM_DEFAULT_CRYPTO_MAP
    Outside_map interface card crypto outside
    crypto ISAKMP allow outside
    crypto ISAKMP policy 10
    preshared authentication
    3des encryption
    md5 hash
    Group 2
    life 86400
    crypto ISAKMP policy 20
    preshared authentication
    3des encryption
    sha hash
    Group 2
    life 86400
    crypto ISAKMP policy 30
    preshared authentication
    aes-256 encryption
    sha hash
    Group 2
    life 86400
    Crypto isakmp nat-traversal 30
    Telnet timeout 5
    SSH 20.20.20.0 255.255.255.0 Inside_1
    SSH 30.30.30.0 255.255.255.0 Inside_2
    SSH timeout 5
    Console timeout 0
    a basic threat threat detection
    Statistics-list of access threat detection
    no statistical threat detection tcp-interception
    WebVPN
    allow outside
    internal DefaultRAGroup group strategy
    attributes of Group Policy DefaultRAGroup
    value of 20.20.20.24 DNS server 30.30.30.35
    Protocol-tunnel-VPN IPSec l2tp ipsec
    Split-tunnel-policy tunnelspecified
    value of Split-tunnel-network-list DefaultRAGroup_splitTunnelAcl
    by default-field value NomDomaine.local
    username password test DLaUiAX3l78qgoB5c7iVNw is encrypted nt
    VPNtest2 password pXVGjB7BA7pQ4yNcDbuXkw user name is nt encrypted
    attributes global-tunnel-group DefaultRAGroup
    address clientVPNpool pool
    ActiveDirectory authentication-server-group
    Group Policy - by default-DefaultRAGroup
    IPSec-attributes tunnel-group DefaultRAGroup
    pre-shared-key *.
    tunnel-group DefaultRAGroup ppp-attributes
    No chap authentication
    ms-chap-v2 authentication
    !
    class-map inspection_default
    match default-inspection-traffic
    !
    !
    type of policy-card inspect dns preset_dns_map
    parameters
    message-length maximum 512
    Policy-map global_policy
    class inspection_default
    inspect the preset_dns_map dns
    inspect the ftp
    inspect h323 h225
    inspect the h323 ras
    inspect the rsh
    inspect the rtsp
    inspect esmtp
    inspect sqlnet
    inspect the skinny
    inspect sunrpc
    inspect xdmcp
    inspect the sip
    inspect the netbios
    inspect the tftp
    inspect the pptp
    World-Policy policy-map
    class inspection_default
    !
    global service-policy global_policy
    context of prompt hostname
    Cryptochecksum:756efffc44ac8f81f4f377567174c15f
    : end

    Hmmm what DPI only on ASA setting and customer?

    It is obviously one of the possibilities.

  • Error 691 connection to MS-CHAP for an ASA5505 HELP! :(

    The firewall is configured for L2TP MSCHAP with RADIUS authentication. It connected fine work then stopped. Here are my troubleshooting so far:

    The configuration of the firewall is perfect (he worked for a while and then stopped so no surprise there), I checked IPSEC is running on my PC, I tested authentication and connecting via VPN client and it works perfectly, the following hotfix is installed on my PC trying to connect:

    http://support.Microsoft.com/kb/980399/en-us

    What else could be wrong?

    It happens to "checking the user name and password... ", then throws me the" Error 691: the remote connection was refused because the combination of name and user password you provided is not recognized, or the selected authentication protocol is not allowed on the remote access server. "

    It may not be the user name and password because I'm logged on the server, create a new user, then that user with the L2TP VPN client group policies group tested and it worked.

    Help me please

    Hi Vicky,

    Yes, the Protocol must match on the server, i.e. the SAA and the type of user authentication. This is the reason why I advise to check whether the user using Radius Authentication and the server have all two MSCHAP.

    I guess that your question has been answered. Please mark the post as answered if everything is ok.

    Thank you

    Delvallée

  • Error 691: The remote connection has been refused

    I'm trying to make the VPN connection in windows 8 surface device to my winserver 2003, but it gives me error

    Error 691: The remote connection was denied because the user name and password combination you provided is not recognized or the selected authentication protocol is not allowed on the remote access server

    In fact, Microsoft has changed the protocols on windows 8. Windows Server 2003 does not include the new Protocol, so it will reject the connection. There is a work around where you can reduce the security of windows 8, so that it can connect VPN on windows 2003 server.

    Parteeks

    Server questions should be asked on the Technet site.

    http://social.technet.Microsoft.com/forums/categories/

  • Out of the blue receiver Error 691

    During the last two weeks started to receive the Error 691, that I have no idea what might have caused this do. Where to start to investigate this repeated error message?  I did something different to the computer is the only thing I used the software "tuneup360" to scan the computer. Thanks for your replies.

    Hello

    Please describe your type of Internet connection used, and how this error.
    http://support.Microsoft.com/kb/314455
    http://www.RealGeek.com/forums/unable-to-correct-DSL-connection-error-691-a-465710.html

  • Unable to connect to the error of MKS

    When I am plugged into the network, I can open the consoles of virtual machines without any problem. However, when I am out of the office and connect to the network via the VPN, it leaves me in vSphere, but when I try to log on to a computer virtual console, I get the error "unable to connect to the MKS. Unable to connect to the server {server name}: 902. Why I open a console when it is connected to the network, but not when I am connected via VPN? Thank you.

    See this KB Article

    http://KB.VMware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalID=749640

  • This connection is an error code: sec_error_unknown_issuer

    Its the this connection is untrusted error, I have recently installed windows 10 but my account is not connected to others and I can not connect to google.com when the firewall is down and disabled. However, I can connect to google.cm I tried to delete the cert.db so that secmod, didn't work uninstalled several times and already have a discount. Also, I can't get into yahoo or most of the other sites like yahoo .com. Also, I can't ping my laptop my modem when I have my windows firewall but with it pings down cross. Honestly, I have no idea what is going on and I can access the same places when I access this computer which also uses firefox and win10.

    Hi ruki114, sorry that it did not work - it wasn't a link of tradtional but should open a certificate installation window in your browser. Alternatively you could have tried the manual procedure described in https://support.microsoft.com/en-us/kb/2965142 in the section about firefox.

    If you don't want to use this feature of family ms anyway, please doublecheck that you disabled it for your account: http://windows.microsoft.com/en-us/windows-10/turn-off-microsoft-family-settings

    If this does not work, could you tell us what software antivirus you are using?

  • Why isn't the exception, I add when I get this connection is untrusted error work?

    I recently started getting "this connection is Untrusted' errors every time I connect to google." Although there is a response describing the problem, I have the solution DOES NOT WORK. Not at all. I added google as an exception, many times, but I still get the same error. Since it doesn't seem to be what I can do in the settings options to confirm that I have indeed added it completely, I want to know why I still keep getting this message despite having already added the site to my exceptions?

    Since you are using Kaspersky, could test you with the disabled HTTPS connection filtering if Kaspersky is the culprit? This should be in the application Kaspersky itself, not in the Firefox Add-ons:

    Settings > others > network

    Uncheck the box for "numerical analysis of connections.

    http://support.Kaspersky.com/images/kis2015_11159_0913-242527.PNG
    http://support.Kaspersky.com/images/kis2015_11144_1813-242648.PNG

  • This connection is untrusted error

    Trouble with my Mac or Mozilla. I get the "this connection is untrusted" on 3/4 of the sites I visit during a session on the internet. I did so that I have to use SSL 3.0 and TLS 1.0 protocols of use checked.

    I could have removed some security certificates or to add some right modules before, I noticed the error message.

    Anyone have any ideas?

    Thank you.

    see this article...

    "This connection is Untrusted" error message - what to do

    ... and let us know if this helped.

  • iPhone 6s won't connect to VPN on work wifi but goes on other wifi networks

    Hello

    I have been connected to my wifi to work for a while and had to use a VPN to use things such as whats'app and access to sites like Facebook. It worked well until what recently just VPN logs not when I am connected to this wifi network. I know that the password etc and I get the symbol wifi at the top of my phone but never impossible to access Web sites (which was normal, but the VPN it fixed), but now I can not connect the VPN even more.

    The VPN application I use is Betternet but I've also tried a few others, none works. However, they all work when I connect to my own wifi network.

    iPhone 6 s - last version of iOS from today (28 Apr 16) cannot find the exact version on my phone

    Pleaseeeeee help me connect to my VPN when I'm on my work wifi

    VPN can be difficult, maybe to consult Betternet. Also see this article for suggestions.

    iOS: setting up VPN - Apple Support

    FWIW here are some general recommendations for Wi - Fi problems, maybe one of them will help you.

    (1) perform a forced reboot: hold the Home and Sleep/Wake buttons simultaneously for about 15-20 seconds, until the Apple logo appears. Leave the device to reboot.

    (2) resetting the network settings: settings > general > reset > reset network settings. Join the network again.

    (3) reboot router/Modem: unplug power for 2 minutes and reconnect. Update the Firmware on the router (support Web site of the manufacturer for a new FW check). Also try different bands (2.4 GHz and 5 GHz) and different bandwidths (recommended for 2.4 to 20 MHz bandwidth).

    (4) change of Google DNS: settings > Wi - Fi > click the network, delete all the numbers under DNS and enter 8.8.8.8 or otherwise 8.8.4.4

    (5) disable the prioritization of device on the router if this feature is available.

    (6) determine if other wireless network devices work well (other iOS devices, Mac, PC).

    (7) try the device on another network, i.e., neighbors, the public coffee house, etc.

    (8) to restore the device (ask for more details if you wish).

    https://support.Apple.com/en-us/HT201252

    (9) go to the Apple Store for the evaluation of the material.

  • HP6510: Connection to Server error-1

    I have the printer wireless HP 6510, who owns the eprint, scanning and different printing applications, that is, disney, etc. I used to be able to use the app and be connected. Everything works except the apps. Whenever I have select this option on the printer screen, I get the error cannot connect to Server error - 1.  Any suggestions you have would be grateully to be exempted excluded me, thank you, Dot

    Hey @DJWeiss,

    Welcome to the Forum from HP Support.

    I see that you are unable to use printable cards via the front panel of your HP Photosmart 6510 e-All-in-One printer. I want to help you with this.

    Front panel inserts have been abandoned on a number of models of printers of this year of release. This means that you will not be able to access this content directly from the printer (without troubleshooting can change that). That said, you can always log on http://www.hpconnected.com/ add your printer to the devices tab and then click on Services and printable to access the same content as before. While this is a different interface, you should still be able to plan the print jobs with the same apps that you liked before.

    I would like to know if this workaround is useful for you. If I helped you to solve the problem and that you liked this post, feel free to give me virtual accessories by clicking on the 'Thumbs Up' icon below by clicking on "accept as Solution" (this will help others find the solution).

    Thanks for posting in the Forum from HP Support.

    Have a great day!

  • When I try to log the p2p soulseek site, I get the error message "connection failed: socket error.» change the connection settings. How can I fix it?

    "socket error".

    When I try to log the p2p soulseek site, I get the error message "connection failed: socket error.» change the connection settings. How can I fix it? Is - this type of error called a winsock error?  It keeps happening to me on this site. What I've read, it happens when you make changes to a program before concluding that under its weight. Could it happen because I'm deleting files, I don't think that will be completed while the other files are D/Ling? That's what I'm doing wrong? I found a solution to correct an error in Winsock that is to enter the "command prompt" and type "netsh winsock. Will this work? (I'm sorry I have so many questions in this post, but I have had TO KNOW!!)

    Hello

    I suggest you send the question here for best support about the issue.

  • Unable to connect to Server error-1 HP 6510

    When I initially installed printer I was able to access the applications, now all I get is an error code that says that I can not connect to Server error - 1.  Is there any solution for this?

    Djenav,

    I wanted to just check and see how things went.

  • Internet connection required: Server error: 0x800CCC90, error number: 0x800CCC92

    Original title:

    Windows Mail in Vista

    Can anyone help please.  I tried to open my email this morning - as usual - and it asks me to enter my username and password.  I did it several times but it won't let me and I get as part of the error message: -.

    Internet connection required: Server error: 0x800CCC90, error number: 0x800CCC92

    I have been in contact with the technicians at Microsoft, but apparently they are more supported Windows Mail.  I can access my mail through my e-mail provider, but it's really annoying!

    Internet connection required:

    This has not preceded by a long and complicated URL that begins with https://accounts... ? The idea is that you must click on the link to log in and verify that it is access you your account by filling out a CAPTCHA. Is that what you did? That's happened?

Maybe you are looking for