Exchange/cisco VPN client failing

I have a WinXP Pro w/Outlook 2003 laptop trying to connect through a Cisco VPN 4.0.5 to the Exchange server. This connection is initiated via a D-link wireless access point. I seem to be having trouble resolving DNS, getting through the firewall, or authenticating to the Exchange server. Outlook gets stuck in "trying to connect". It only seems to be problematic from this one location, so perhaps it's a firewall port I'm missing...although I've followed all D-link instructions for enabling this Cisco client at

formatting link
Closest I've come to solving this is using the following KB article tells me that MS04-11 update may create this problem, but I can't uninstall it as it appears to have come with SP2 or another roll-up. I've tried the uninstall switch, before and after trying to reinstall it alone:

formatting link
Here are my log entries:

Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40960 Date: 5/13/2006 Time: 8:10:50 PM User: N/A Computer: FNL-001 Description: The Security System detected an attempted downgrade attack for server exchangeAB/HQ-MAIL-VS2.company.net. The failure code from authentication protocol Kerberos was "No authority could be contacted for authentication. (0x80090311)".

For more information, see Help and Support Center at

formatting link
Event Type: Warning Event Source: DnsApi Event Category: None Event ID: 11197 Date: 5/13/2006 Time: 8:10:50 PM User: N/A Computer: FNL-001 Description: The system failed to update and remove host (A) resource records (RRs) for network adapter with settings:

Adapter Name : {C8886BF1-FC23-4B35-93B8-C435EADD2B02} Host Name : fnl-001 Primary Domain Suffix : company.net DNS server list : 10.0.0.15, 10.0.0.13 Sent update to server : 10.1.1.1 IP Address(es) : 10.0.30.120

The reason the update request failed was because of a system problem. For specific error code, see the record data displayed below.

For more information, see Help and Support Center at

formatting link

0000: 1e 25 00 00 .%..

Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40961 Date: 5/13/2006 Time: 8:10:50 PM User: N/A Computer: FNL-001 Description: The Security System could not establish a secured connection with the server exchangeAB/hq-MAIL-VS2.company.net. No authentication protocol was available.

For more information, see Help and Support Center at

formatting link

Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40960 Date: 5/13/2006 Time: 8:10:54 PM User: N/A Computer: FNL-001 Description: The Security System detected an attempted downgrade attack for server exchangeMDB/hq-MAIL-VS2.company.net. The failure code from authentication protocol Kerberos was "There are currently no logon servers available to service the logon request. (0xc000005e)".

For more information, see Help and Support Center at

formatting link

Event Type: Warning Event Source: LSASRV Event Category: SPNEGO (Negotiator) Event ID: 40961 Date: 5/13/2006 Time: 8:10:54 PM User: N/A Computer: FNL-001 Description: The Security System could not establish a secured connection with the server exchangeMDB/hq-MAIL-VS2.company.net. No authentication protocol was available.

For more information, see Help and Support Center at

formatting link

Reply to
DC Gringo
Loading thread data ...

If pinging to the server is fine that means you are half way there. Please give the info regarding your VPN gateway.

Gut feel is that it is a MTU problem.

-Vikas

Reply to
sampark

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.