Event ID 20209 — RRAS Other Remote Access Server Configurations

Applies To: Windows Server 2008

Successful remote access and routing connections require the correct configuration of firewall settings and IP routing protocols.

Event Details

Product: Windows Operating System
ID: 20209
Source: RemoteAccess
Version: 6.0
Message: A connection between the VPN server and the VPN client: %1 has been established but the VPN connection cannot be completed. The most common cause for this is that a firewall or router between the VPN server and the VPN client is not configured to allow Generic Routing Encapsulation (GRE) packets (protocol 47).


Configure the firewall to allow GRE traffic

To allow PPTP traffic, configure the network firewall to open TCP port 1723 and to forward IP protocol 47 for Generic Routing Encapsulation (GRE) traffic to the VPN server. Some firewalls refer to IP protocol 47 as VPN or PPTP pass-through. Not all firewalls support IP protocol 47. You might need to upgrade the firmware.

Consider using Secure Socket Tunneling Protocol (SSTP), which uses the HTTPS protocol over TCP port 443 to pass traffic through firewalls and Web proxies that might block PPTP and L2TP/IPsec traffic.


To verify that the remote access server can accept connections, establish a remote access connection from a client computer.

To create a VPN connection:

  1. Click Start, and then click Control Panel.
  2. Click Network and Internet, click Network and Sharing Center, and then click Set up a connection or network.
  3. Click Connect to a workplace, and then click Next.
  4. Complete the steps in the Connect to a Workplace wizard.

To connect to a remote access server:

  1. In Network and Sharing Center, click Manage network connections.
  2. Double-click the VPN connection, and then click Connect.
  3. Verify that the connection was established successfully.

RRAS Other Remote Access Server Configurations

Routing and Remote Access Service Infrastructure