Internal CA only issues certs on one subnet

A

AfghanDan

We've setup the Always-On VPN for our Windows 10 users and it works fine. Our CA is in head office, we have 5 remote sites all with VPN links between them, no firewalls as such so all traffic flows between all the sites. We can ping the CA (Which is also a DC running 2016) at the HQ from all remote sites, we can RDP to it, browse the file shares on it etc so I don't believe it's a connectivity issue.

The user certificate template however is only issued to the users when they are physically on the HQ LAN/Subnet. From all other offices it just never gets assigned to them. I have tested this with a few users over a few weeks. They do not have the certificate, but if I physically drive to HQ, plug in the laptop and wait a short while, then the VPN certificate is installed on the machine automatically.

I'm sure it's something simple I am missing. Any suggestions?

Continue reading...
 
Back
Top Bottom