We have a VPN concetrator that we use the Active Directory/Kerberos authentication with to authenticate users. It worked fine on our WIndows 2000 domain controller, but now that we are using Windows 2003, it will not allow any users to authenticate.
I am sure that I have it setup correctly on the concentrator side because I can change the authentication server IP address back to one of the WIndows 2000 domain controllers and it immediately starts working again. When I go back to the Windows 2003 DC, then it fails. I have used the test button and have tried to use the vpn client.
Does anyone know if there is a change between kerberos on Windows 2000 and WIndows 2003? Is there something I would need to change on the new WIndows 2003 server to make it work. I guess my other option is to setup IAS on the server and do RADIUS, but it seems like this should be able to work. Any ideas would be greatly appreciated!
Thanks,
Josh