Troubleshooting Always On VPN di Windows 11 biasanya berakhir di salah satu dari empat penyebab: profil VPN yang hilang setelah update Intune, error 809 karena port UDP 500/4500 diblokir NAT, error 812 karena mismatch metode autentikasi di NPS, atau Device Tunnel yang gagal auto-connect karena device bukan Windows 11 Enterprise atau tidak domain-joined. Panduan ini adalah alur diagnostik yang saya pakai di helpdesk MSP untuk menyelesaikan tiket AOVPN dalam kurang dari 15 menit, mulai dari mengumpulkan log RasClient sampai memperbaiki ProfileXML yang rusak lewat OMA-URI.
Kumpulkan tiga bukti dulu sebelum utak-atik: Event ID RasClient (Application log), Get-VpnConnection -AllUserConnection, dan output rasdial. Sekitar 80% tiket bisa dituntaskan dari sini.
Error 809 hampir selalu tentang UDP 500/4500 diblokir atau NAT-T tidak diaktifkan. Solusinya bukan ganti server, tapi tambahkan registry AssumeUDPEncapsulationContextOnSendRule = 2.
Error 812 dan Event ID 20227 di RasClient menandakan mismatch metode EAP antara profil client dan NPS policy. Bandingkan EAP-Config XML dan Network Policy secara berdampingan.
Device Tunnel wajib Windows 11 Enterprise plus domain-joined (atau Hybrid Entra Join). Di Pro Edition dia terpasang tapi tidak auto-connect.
Untuk deployment via Intune, custom OMA-URI dengan ProfileXML jauh lebih andal daripada template VPN bawaan karena template UI tidak mengekspos semua node VPNv2 CSP.
Setelah April 2024, banyak device Enterprise via subscription activation "kembali" ke Pro dan mematikan Device Tunnel. Install KB5040527 atau update lebih baru untuk fix subscription revert.
Alur diagnostik AOVPN dalam 5 menit
Jujur saja, ketika tiket masuk dengan judul "VPN tidak connect", saya selalu mulai dari tiga pertanyaan yang menutup 90% skenario sebelum menyentuh registry: (1) apakah Device Tunnel connect tapi User Tunnel tidak, atau sebaliknya? (2) apakah masalahnya konsisten di semua network (kantor, rumah, hotspot) atau hanya di satu tempat? (3) apakah error code yang muncul di RasClient adalah 809 (network), 812 (auth), 691 (credential), atau 13801 (certificate)? Jawaban ketiga pertanyaan itu langsung mempersempit ke satu dari empat cabang di flowchart AOVPN.
Contoh nyata dari tiket bulan lalu. Device Tunnel connect tapi User Tunnel error 812, hanya di rumah, hanya untuk satu user. Bisa dipastikan certificate user expired atau NPS policy tidak mencakup group user tersebut. Sebaliknya, User Tunnel connect di kantor tapi tidak di jaringan luar dengan error 809? Hampir pasti UDP 500/4500 di router client diblokir dan NAT-T belum di-enable via registry. Menyempitkan cabang di awal jauh lebih cepat daripada langsung menjalankan Reset-VpnConnection yang sering justru menghapus ProfileXML yang benar. Untuk lingkungan hybrid dengan Conditional Access, saya juga selalu cross-check dengan policy Conditional Access untuk Entra ID. Banyak kasus "VPN putus" ternyata Conditional Access blok karena device compliance state basi.
Mengumpulkan log yang benar (RasClient, NPS, IKEEXT)
Tanpa log yang benar, troubleshooting AOVPN adalah menebak-nebak. Ada empat sumber log yang saya buka pertama kali di setiap tiket, dan urutannya penting karena satu log sering menunjuk ke log berikutnya:
Application log di client. Filter berdasarkan source RasClient. Event ID 20227 mencatat kegagalan koneksi dengan error code numerik (809, 812, 13801, dll). Event ID 20226 mencatat koneksi berhasil untuk konfirmasi.
System log di client. Filter berdasarkan source IKEEXT. Event ID 4653 menampilkan detail negosiasi IKE yang gagal, termasuk cipher suite mismatch atau timeout Phase 1.
Security log di NPS server. Filter Event ID 6273 (autentikasi ditolak) dan 6272 (autentikasi diterima). Reason Code di sini adalah kunci: 16 (credential mismatch), 22 (EAP method rejected), 66 (client cert invalid).
Trace CAPI2 di client untuk masalah sertifikat. Enable via Event Viewer > Applications and Services Logs > Microsoft > Windows > CAPI2 > Operational, klik kanan lalu Enable Log.
Kumpulkan snapshot log ke satu file dengan PowerShell berikut, lalu attach ke tiket sebelum eskalasi:
Error 809 muncul dengan pesan "The network connection between your computer and the VPN server could not be established because the remote server is not responding." Ini adalah error konektivitas layer 3/4, bukan autentikasi, jadi jangan ganti password atau certificate dulu. Penyebab paling umum di lingkungan 2026 adalah UDP port 500 (IKE) dan 4500 (NAT-T) diblokir oleh router client, firewall corporate, atau ISP; dan client berada di belakang NAT tapi Windows belum diberi tahu untuk mengaktifkan IPsec NAT Traversal.
Perbaikan yang paling sering berhasil adalah menambahkan registry key AssumeUDPEncapsulationContextOnSendRule. Nilai 2 berarti Windows akan membangun encrypted channel meskipun client dan server sama-sama di belakang NAT. Perilaku default Windows 11 justru menolak skenario ini demi keamanan, yang tidak realistis untuk work-from-home:
# Aktifkan IPsec NAT-T untuk client di belakang NAT (fix untuk error 809)
# Jalankan sebagai Administrator, restart wajib setelahnya
New-ItemProperty `
-Path "HKLM:\SYSTEM\CurrentControlSet\Services\PolicyAgent" `
-Name "AssumeUDPEncapsulationContextOnSendRule" `
-Value 2 `
-PropertyType DWord `
-Force
# Verifikasi
Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Services\PolicyAgent" `
| Select-Object AssumeUDPEncapsulationContextOnSendRule
Restart-Computer
Kalau setelah reboot error 809 tetap muncul, cek dua hal berikutnya secara berurutan. Pertama, test dari network berbeda (tethering HP) untuk memisahkan apakah masalahnya di ISP/router user atau di infrastruktur. Kedua, test resolusi DNS dan reachability port dari client dengan Test-NetConnection vpn.contoh.com -Port 500 -InformationLevel Detailed. Kalau TCP test hijau tapi UDP tidak bisa dites, minta network team konfirmasi UDP 500/4500 reachable. Kadang firewall corporate hanya membuka TCP 443 untuk SSTP dan Anda pikir profil sudah IKEv2 padahal sebenarnya dia fallback ke SSTP dan gagal karena SSTP butuh certificate chain yang benar.
Cara mengatasi error 812 dan mismatch autentikasi EAP
Error 812 berbunyi: "The connection was prevented because of a policy configured on your RAS/VPN server. Specifically, the authentication method used by the server to verify your username and password may not match the authentication method configured in your connection profile." Terjemahannya di lapangan: metode EAP di ProfileXML client tidak diterima oleh Network Policy di NPS. Ini bukan bug, ini konfigurasi yang tidak sinkron.
Alur diagnostik yang saya pakai ada dua tahap. Pertama, di NPS server, buka Event Viewer > Custom Views > Server Roles > Network Policy and Access Services. Cari Event ID 6273 pada timestamp attempt user, catat "Reason Code". Nilai 22 berarti "The client could not be authenticated because the Extensible Authentication Protocol (EAP) Type cannot be processed by the server," yang mengkonfirmasi mismatch. Kedua, di client, export EAP-Config XML dari profil aktif dan bandingkan dengan yang di-expect NPS. Untuk ProfileXML yang di-deploy via Intune OMA-URI, EapConfiguration node harus persis match dengan NPS Network Policy, termasuk EAP method (13 untuk EAP-TLS, 25 untuk PEAP), inner method untuk PEAP (26 untuk MS-CHAPv2), dan trusted root certificate authority thumbprint.
Untuk generate EAP-Config XML yang benar dari client yang sudah bekerja lalu embed ke ProfileXML:
# Export EAP-Config dari koneksi VPN yang sudah berhasil connect
# Gunakan hasilnya untuk mengganti node EapConfiguration di ProfileXML
$vpnName = "Corp-User-Tunnel"
# Buat template koneksi manual dulu di Windows Settings dengan setting EAP yang benar,
# lalu jalankan:
$conn = Get-VpnConnection -Name $vpnName
$xml = $conn.EapConfigXmlStream
# Simpan ke file untuk copy-paste ke ProfileXML Intune
$xml | Out-File "$env:USERPROFILE\Desktop\eap-config.xml" -Encoding UTF8
# Bandingkan dengan yang di NPS Network Policy
Write-Host "Buka NPS Console > Network Policies > [policy Anda] > Constraints > Authentication Methods"
Write-Host "Pastikan EAP type yang tercantum sama dengan yang di file eap-config.xml"
Kesalahan spesifik yang sering saya lihat: NPS policy dibatasi ke satu group AD (misalnya VPN-Users) tapi user yang error belum masuk group tersebut, atau tenant sedang migrasi Hybrid Join dan user object di on-prem AD belum sync ke Entra ID. Cek sync status via Sync-ADObject atau Azure AD Connect Sync Manager sebelum menyalahkan sertifikat.
Kenapa Always On VPN Device Tunnel tidak connect otomatis?
Device Tunnel adalah komponen AOVPN yang connect sebelum user login sehingga Group Policy, Intune remediation, dan wake-on-LAN corporate dapat berfungsi tanpa user harus autentikasi dulu. Kalau dia tidak connect otomatis, ada empat prasyarat yang wajib dicek berurutan sebelum melihat konfigurasi ProfileXML:
Windows 11 Enterprise Edition. Bukan Pro, bukan Education. Cek dengan Get-ComputerInfo | Select-Object OsName, WindowsEditionId. Kalau Pro, Device Tunnel akan terinstall tapi tidak auto-connect.
Domain-joined atau Hybrid Entra Joined. Bukan Entra Joined saja. Untuk hybrid, jalankan dsregcmd /status dan konfirmasi DomainJoined : YES dan AzureAdJoined : YES.
Certificate device di LocalMachine\My di-issue oleh internal CA, dengan Client Authentication EKU, dan private key bisa diakses SYSTEM.
Deploy dalam System context. Device Tunnel harus dibuat via PowerShell.exe berjalan sebagai NT AUTHORITY\SYSTEM (pakai psexec -s atau Intune Win32 app), bukan sebagai user admin.
Insiden yang cukup mahal untuk kami pada 2024-2025: setelah April 2024 security update, banyak device yang di-upgrade ke Enterprise via subscription activation "kembali" ke Pro Edition secara diam-diam. Device Tunnel yang sebelumnya bekerja tiba-tiba mati untuk beberapa ratus laptop. Fix-nya adalah install KB5040527 atau update kumulatif lebih baru, kemudian force subscription activation ulang. Untuk debugging Device Tunnel yang tidak start setelah semua prasyarat terpenuhi, hapus registry key HKLM:\SYSTEM\CurrentControlSet\Services\RasMan\DeviceTunnel\ lalu re-deploy. Windows menyimpan state lama di sini yang kadang blok rebuild.
Kenapa profil VPN hilang setelah update Intune?
Salah satu keluhan paling sering di Windows 11 versus Windows 10 adalah profil AOVPN yang deploy via Intune tiba-tiba hilang, biasanya setelah admin mengedit dan re-assign profil. Root cause-nya: ketika Anda mengubah setting di profil Intune yang sudah ter-assign, Intune menghapus profil lama di client dulu, baru push profil baru. Window "kosong" ini bisa 5 sampai 30 menit tergantung MDM sync interval. Selama window itu, user melihat "koneksi tidak ditemukan."
Ada tiga langkah mitigasi yang saya rekomendasikan untuk tim yang deploy AOVPN via Intune di 2026:
Selalu pakai custom OMA-URI dengan ProfileXML, bukan template VPN bawaan. Template UI Intune tidak mengekspos semua node VPNv2 CSP dan lebih rentan overwrite. Path OMA-URI: ./User/Vendor/MSFT/VPNv2/<NamaKoneksi>/ProfileXML untuk User Tunnel, ./Device/Vendor/MSFT/VPNv2/<NamaKoneksi>/ProfileXML untuk Device Tunnel.
Jangan pakai hyphen di nama koneksi OMA-URI. Ini bug lama yang menghasilkan Syncml(425) error. Pakai underscore atau CamelCase. Contoh: CorpUserTunnel, bukan Corp-User-Tunnel.
Trigger manual MDM sync setelah edit profil. Instruksikan user buka Settings > Accounts > Access work or school > klik akun Work > Info > Sync. Atau via PowerShell: jalankan skrip di bawah.
# Force Intune MDM sync tanpa harus buka Settings GUI
# Berguna untuk mempercepat re-deploy profil AOVPN setelah edit di Intune
$mdmTask = "PushLaunch"
$taskPath = "\Microsoft\Windows\EnterpriseMgmt\"
Get-ScheduledTask -TaskPath "$taskPath*" |
Where-Object { $_.TaskName -eq $mdmTask } |
ForEach-Object {
Write-Host "Trigger sync untuk $($_.TaskPath)"
Start-ScheduledTask -InputObject $_
}
# Cek status sync
Get-WinEvent -LogName "Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin" `
-MaxEvents 20 | Format-Table TimeCreated, Id, Message -AutoSize
Kalau profil tetap tidak muncul setelah sync, cek Event ID 404 di log Enterprise-Diagnostics-Provider. Ini menandakan XML parse error di sisi client. Error 0x87d1fde8 biasanya berarti ProfileXML Anda mengandung karakter yang tidak di-escape dengan benar (ampersand harus &, kurang siku <) atau ada BOM di file XML yang di-upload ke Intune. Lihat panduan troubleshooting Intune Autopilot Windows 11 untuk pattern debugging Intune yang lebih luas. Banyak dari pattern itu berlaku juga untuk AOVPN.
Deploy AOVPN via Intune dengan ProfileXML dan OMA-URI
Untuk deployment baru di 2026, saya selalu pakai custom OMA-URI dengan ProfileXML karena empat alasan: (1) semua node VPNv2 CSP tersedia, (2) EAP-Config XML bisa embed persis sesuai NPS policy, (3) TrustedNetworkDetection bisa dikonfigurasi supaya VPN tidak connect ketika user di corporate Wi-Fi, (4) Device Tunnel dan User Tunnel bisa di-package dalam dua profil terpisah dengan naming convention yang jelas. Template Intune bawaan tidak mengekspos DeviceTunnel atau TrustedNetworkDetection.
Contoh minimal ProfileXML untuk User Tunnel dengan EAP-TLS, split tunneling, dan Trusted Network Detection:
Cara embed ke Intune ada tiga langkah. Encode ProfileXML di atas (semua < jadi <, semua > jadi >, semua & jadi &), tapi jangan encode dua kali. Di Intune Admin Center > Devices > Configuration > Create profile, pilih Windows 10 and later > Templates > Custom. Tambah OMA-URI setting dengan path yang sesuai (User atau Device), Data type: String (XML file), lalu upload file .xml. Gunakan file upload, jangan copy-paste string XML. Copy-paste sering menambahkan BOM atau normalisasi whitespace yang merusak parsing. Refer ke panduan resmi Microsoft Deploy Always On VPN profile via Intune dan dokumentasi VPNv2 CSP untuk daftar lengkap node dan nilai valid.
Bug PEAP di Windows 11 26H1
Sejak April 2026, ada bug dikonfirmasi di Windows 11 build 26H1 yang menyebabkan semua koneksi VPN dengan Protected EAP (PEAP) gagal, baik Always On VPN maupun koneksi manual/ad-hoc. Error yang muncul di RasClient adalah Event ID 20227 dengan subcode 0x80072746 atau timeout Phase 2. Root cause-nya ada di implementasi baru SChannel yang tidak toleran terhadap TLS renegotiation pattern yang dipakai server NPS lawas.
Workaround sementara sampai Microsoft rilis patch ada dua opsi. Pertama, migrasi profil ke EAP-TLS certificate-based authentication. Ini best practice untuk 2026 juga karena PEAP dengan MS-CHAPv2 sudah dianggap deprecated untuk enterprise. Kedua, tunda deployment 26H1 di ring produksi via Windows Update for Business. Jangan skip update, tapi tahan di ring pilot 2 sampai 4 minggu sampai konfirmasi dari komunitas AOVPN. Cek Richard Hicks post tentang bug PEAP 26H1 untuk tracking status patch. Kombinasi bug 26H1 dan policy kadang membingungkan dengan masalah Group Policy tidak diterapkan di Windows 11, terutama kalau GPO yang mengonfigurasi certificate autoenrollment gagal jalan tanpa VPN. Perhatikan urutan cause-and-effect.
Checklist eskalasi sebelum melempar tiket ke network team
Salah satu hal yang paling menyakitkan sebagai team lead helpdesk adalah tiket yang dilempar ke network team tanpa data. Sebelum mengeskalasikan tiket AOVPN, saya minta tim untuk selalu melampirkan tujuh artefak berikut. Kalau ada satu yang kosong, tolak eskalasinya:
Output Get-VpnConnection -AllUserConnection | Format-List dan Get-VpnConnection | Format-List.
Event log RasClient (Application) dan IKEEXT (System) 24 jam terakhir. Pakai script pengumpul di section Mengumpulkan log.
Screenshot Error ID dan message persis, bukan parafrase user.
Output Test-NetConnection vpn.contoh.com -Port 443 dan Test-NetConnection vpn.contoh.com -Port 500 dari client saat kondisi bermasalah.
Konfirmasi apakah masalah reproducible di network lain (tethering HP, hotspot cafe).
Nomor Windows build (winver) dan edition (Get-ComputerInfo | Select WindowsEditionId).
Certificate snapshot: Get-ChildItem Cert:\LocalMachine\My dan Cert:\CurrentUser\My, cek NotAfter untuk certificate expiration.
Dengan tujuh artefak di atas, network team bisa langsung masuk ke firewall log dan NPS log tanpa harus interview user berjam-jam. Ini juga proteksi bagi tim helpdesk: kalau masalahnya ternyata di firewall corporate, Anda punya bukti kuat bahwa client-side sudah bersih.
Pertanyaan yang Sering Diajukan
Apa perbedaan Device Tunnel dan User Tunnel di Always On VPN?
Device Tunnel connect sebelum user login menggunakan certificate device, sehingga Group Policy dan Intune remediation dapat dijalankan tanpa user harus autentikasi dulu. User Tunnel connect setelah user login menggunakan certificate atau credential user, dan biasanya membawa access ke resource user-specific seperti file share. Deployment umum di enterprise menggunakan keduanya bersamaan: Device Tunnel untuk management, User Tunnel untuk akses aplikasi.
Apakah Always On VPN gratis dari Microsoft?
Ya, komponen AOVPN itu sendiri (RRAS di Windows Server, VPN client di Windows) tidak butuh lisensi tambahan. Yang butuh lisensi adalah Windows Server yang menjalankan RRAS dan NPS, serta Windows 11 Enterprise di sisi client kalau Anda butuh Device Tunnel auto-connect. Certificate authority internal juga tidak butuh lisensi tambahan. Active Directory Certificate Services termasuk role gratis di Windows Server.
Bagaimana cara test Always On VPN sebelum di-deploy ke seluruh organisasi?
Buat pilot group berisi 10 sampai 20 device dengan mix edition (Enterprise dan Pro untuk memastikan Device Tunnel behavior), mix network (kantor, remote, tethering), dan mix user role (executive, road warrior, developer). Assign profil Intune ke group ini dulu selama minimal 2 minggu sebelum broad rollout. Track ticket volume dan Event ID 20227 count via Intune reports untuk baseline health metric.
Apakah AOVPN bisa jalan bersamaan dengan third-party VPN seperti GlobalProtect atau Cisco AnyConnect?
Secara teknis bisa, tapi tidak direkomendasikan. Multiple VPN client dapat konflik di routing table dan menyebabkan asymmetric routing yang sulit di-debug. Kalau Anda migrasi dari GlobalProtect ke AOVPN, uninstall GlobalProtect dulu sebelum push profil AOVPN. Kalau butuh kedua VPN untuk kasus temporary, dokumentasikan dengan jelas dan monitor connectivity issue lebih ketat.
Kenapa VPN saya connect tapi tidak bisa akses internal resource?
Tiga penyebab paling umum: (1) split tunnel dikonfigurasi tapi route ke subnet internal tidak di-include di ProfileXML, cek node Route, (2) DNS suffix atau DNS server internal tidak di-push ke client, cek node DnsSuffix dan DomainNameInformation, (3) firewall internal blok subnet client VPN, koordinasi dengan network team untuk cek ACL. Jalankan ipconfig /all saat VPN connect untuk verifikasi DNS dan route yang dipush.
Marcus spent 11 years on enterprise helpdesks before moving into MSP team lead work - first at a 400-seat law firm running a hybrid AD/Entra environment, then four years at Rackspace handling escalations for mid-market M365 tenants. He holds MS-102 (Microsoft 365 Administrator Expert) and the older MCSA: Windows Server, and writes most of the Intune and Conditional Access material here.
His subspecialty is the messy middle of M365 migrations: tenant-to-tenant moves, the OneDrive known-folder-move rollout that breaks half a department's desktop shortcuts, and the Conditional Access policy that locks the CEO out at 6am on a Monday. He has personally rebuilt three Exchange hybrid configurations after botched cutovers and still keeps a printed copy of the Hybrid Configuration Wizard logs on his desk as a warning.
Outside work he restores 1990s ThinkPads and runs a small home lab on refurbished Dell R730s.
Panduan lengkap troubleshooting account lockout Active Directory 2026 untuk tim helpdesk: temukan source computer via Event ID 4740, LockoutStatus, PowerShell, dan otomatisasi investigasi dengan Power Automate. Termasuk runbook 15 menit siap pakai.
Autopilot Windows 11 stuck di ESP atau melempar 0x80180018? Panduan troubleshoot Intune Autopilot 2026: prasyarat lisensi, upload hardware hash via Graph, cara baca log Intune Management Extension, dan metrik MTTR yang wajib dilacak helpdesk.
Panduan lengkap tim helpdesk untuk memperbaiki masalah sync email, kalender, dan add-in COM di New Outlook Windows 2026. Termasuk runbook PowerShell, checklist eskalasi 15 menit, dan timeline migrasi resmi dari Classic Outlook.