We are having issues with RADIUS authentication for PPTP and L2TP (on a Sophos UTM SG 550, version 9.701-6), VPN users are able to authenticate without any issues, our issue is when a users password expires or we force a password change they are not prompted to say their password as expired/change required and to set a new one, the network policy on the radius server though does have "User can change password after it has expired" enabled. Is this a limitation on the UTM that doesnt allow this feature?. The radius server is on a Domain Controller and on Windows Server 2012r2. The users connect to the VPN using the Windows 10 inbuilt VPN connection. All the end user gets when their password as expired or we have forced a password change is the error "The remote connection was denied because the user name and password combination you provided is not recognized, or the select authentication protocol is not permitted on the remote access server". This is a feature that we have never managed to get working, i have logged a ticket with support but they just state its an issue with the radius server which i guess it could well be, but just looking if anyone does have this working and any ideas what the issue or could.
This thread was automatically locked due to age.