Help needed: VPN authentication with Open Directory Master

PierreDaubresse

Registered
Hi All,

Maybe someone already met this problem and could help me:
I have an Xserve running Mac OS X Tiger Server, which is called WOZ. Open Directory is active on this server, and is connected to a domain server, which is called JOBS. Therefore, any person connecting to the WOZ server will be authenticated against the user database (LDAP) hosted on JOBS.
So, I activated VPN on the server WOZ, and tried to connect to it from an iBook running Tiger. But it doesn't work, and I receive the following message:

2005-12-12 10:24:36 CET Incoming call... Address given to client = 192.168.20.210
Mon Dec 12 10:24:36 2005 : Directory Services Authentication plugin initialized
Mon Dec 12 10:24:36 2005 : Directory Services Authorization plugin initialized
Mon Dec 12 10:24:36 2005 : L2TP incoming call in progress
Mon Dec 12 10:24:36 2005 : L2TP received SCCRQ
Mon Dec 12 10:24:36 2005 : L2TP sent SCCRP
Mon Dec 12 10:24:36 2005 : L2TP received SCCCN
Mon Dec 12 10:24:36 2005 : L2TP received ICRQ
Mon Dec 12 10:24:36 2005 : L2TP sent ICRP
Mon Dec 12 10:24:36 2005 : L2TP received ICCN
Mon Dec 12 10:24:36 2005 : L2TP connection established.
Mon Dec 12 10:24:36 2005 : using link 0
Mon Dec 12 10:24:36 2005 : Using interface ppp0
Mon Dec 12 10:24:36 2005 : Connect: ppp0 <--> socket[34:18]
Mon Dec 12 10:24:36 2005 : sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0xba2f95a7> <pcomp> <accomp>]
Mon Dec 12 10:24:37 2005 : rcvd [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0x7206e46c> <pcomp> <accomp>]
Mon Dec 12 10:24:37 2005 : lcp_reqci: returning CONFACK.
Mon Dec 12 10:24:37 2005 : sent [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0x7206e46c> <pcomp> <accomp>]
Mon Dec 12 10:24:39 2005 : sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0xba2f95a7> <pcomp> <accomp>]
Mon Dec 12 10:24:39 2005 : rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0xba2f95a7> <pcomp> <accomp>]
Mon Dec 12 10:24:39 2005 : sent [LCP EchoReq id=0x0 magic=0xba2f95a7]
Mon Dec 12 10:24:39 2005 : sent [CHAP Challenge id=0xab <d868401c2682d4fd3535edeb56021047>, name = "woz"]
Mon Dec 12 10:24:39 2005 : rcvd [LCP EchoReq id=0x0 magic=0x7206e46c]
Mon Dec 12 10:24:39 2005 : sent [LCP EchoRep id=0x0 magic=0xba2f95a7]
Mon Dec 12 10:24:39 2005 : rcvd [LCP EchoRep id=0x0 magic=0x7206e46c]
Mon Dec 12 10:24:39 2005 : rcvd [CHAP Response id=0xab <d4b5c078ee344cfd53e92760185661fc000000000000000092c39b794e8184247e288b305fd42ebabcbdcffc94397d3000>, name = "username"]
Mon Dec 12 10:24:39 2005 : Peer username failed CHAP authentication
Mon Dec 12 10:24:39 2005 : sent [CHAP Failure id=0xab "\37777777677\37777777777\37777777771\37777777760"]
Mon Dec 12 10:24:39 2005 : sent [LCP TermReq id=0x2 "Authentication failed"]
Mon Dec 12 10:24:40 2005 : rcvd [LCP TermReq id=0x2 "Failed to authenticate ourselves to peer"]
Mon Dec 12 10:24:40 2005 : sent [LCP TermAck id=0x2]
Mon Dec 12 10:24:40 2005 : rcvd [LCP TermAck id=0x2]
Mon Dec 12 10:24:40 2005 : Connection terminated.
Mon Dec 12 10:24:40 2005 : L2TP disconnecting...
Mon Dec 12 10:24:40 2005 : L2TP sent CDN
Mon Dec 12 10:24:40 2005 : L2TP sent StopCCN
Mon Dec 12 10:24:40 2005 : L2TP disconnected
2005-12-12 10:24:40 CET --> Client with address = 192.168.20.210 has hungup

If I create an account in the local NetInfo database of the WOZ server, VPN works. So the problem seems due to the fact that the WOZ server is authenticating against the LDAP database of server JOBS. I checked in the Open Directory config of server JOBS, and MS-CHAPv2 is activated.
So what's wrong?

Thanks in advance for any advice,

Pierre
 
Back
Top