Forum Discussion
Windows 11 Always on VPN device tunnel removed on reboot
If yes, check the event viewer and see if there is any relevant log files there.
I believe this is a bug and try open Feedback Hub app in Windows 11 and report this issue.
- Tstevenson1615Nov 12, 2021Copper ContributorAlso happening in our environment!
- Reza_AmeriNov 13, 2021Silver ContributorFrom the discussion here, I believe this is a bug and make sure file a bug report.
- SPSBjornNov 23, 2021Copper ContributorCan confirm this issue on Windows 11. At Intune Sync the VPN gets removed, next sync created, next sync deleted etc etc in a loop.
Event ID 601: MDM ResourceManager: DeleteResource EnrollmentID: (47D9D99A-C0C6-4AD1-978B-D1BE2126AXXX) UserSID: (S-1-12-1-1214335156-1177976991-1889557148-3126361797) URI: (./Vendor/MSFT/VPNv2/AOVPN).
and than:
Event ID 404: MDM ConfigurationManager: Command failure status. Configuration Source ID: (47D9D99A-C0C6-4AD1-978B-D1BE2126XXXX), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (VPNv2), Command Type: (Add: from Replace or Add), CSP URI: (./User/Vendor/MSFT/VPNv2/AOVPN), Result: (The specified quota list is internally inconsistent with its descriptor.).
- jjeffriesAug 23, 2021Copper Contributor
Reza_Ameri
Yes that's correct, admittedly we haven't tried on a fresh install of windows 11 only on an upgrade (for our environment 90% will be upgraded in the future).
I have been playing with it over the weekend as well and can also confirm i can replicate the issue if the device goes to sleep too.
As for event view logs, i am seeing event id 233, the first being - The operation 'Delete' succeeded on nic 539A6C2E-3B4E-4AE3-9FA4-45218E7CB927 (Friendly Name: Always On VPN -), Instance Id {6da09a8c-62a3-4fdd-87b9-15904318d2b9}.
with subsequent redeploy events of:
The operation 'Create' succeeded on nic 247A8E96-70BB-4EE5-88F1-8C0012190023 (Friendly Name: Always On VPN -), Instance Id {00000000-0000-0000-0000-000000000000}.
Miniport NIC 247A8E96-70BB-4EE5-88F1-8C0012190023 (Friendly Name: Always On VPN -) successfully initialized.
NIC 247A8E96-70BB-4EE5-88F1-8C0012190023 (Friendly Name: Always On VPN -) successfully connected to port 13370ECB-0D6A-4E9C-8DB0-F64170BDC969 (Friendly Name: Container NIC 23ca8c04) on switch C08CB7B8-9B3C-408E-8E30-5E16A3AEB444(Friendly Name: Default Switch).
on the intune logs i can see a couple of errors which could relate (although i am not entirely sure what they mean...)
MDM ConfigurationManager: Command failure status. Configuration Source ID: (C664FCF1-D9FD-4FC4-8258-AF86250964CB), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (VPNv2), Command Type: (Clear: first phase of Delete), CSP URI: (./Device/Vendor/MSFT/VPNv2/Always On VPN - Device Tunnel), Result: (An attempt was made to reference a token that does not exist.).
MDM ConfigurationManager: Command failure status. Configuration Source ID: (C664FCF1-D9FD-4FC4-8258-AF86250964CB), Enrollment Name: (MDMDeviceWithAAD), Provider Name: (VPNv2), Command Type: (Add: from Replace or Add), CSP URI: (./Device/Vendor/MSFT/VPNv2/Always On VPN - Device Tunnel), Result: (The specified quota list is internally inconsistent with its descriptor.).- SinceVanillaOct 25, 2021Copper Contributor+1
- Reza_AmeriAug 23, 2021Silver ContributorFrom what you discussed, this is a bug in Windows 11 and I advise you to report this issue using Feedback Hub app so the Windows team would be able to investigate it.
- jjeffriesAug 23, 2021Copper ContributorAlready raised 🙂 thanks Reza