DirectAccess安装错误:错误:无法从DirectAccess服务器GPO检索configuration设置

我正在使用向导在Windows Server 2012上安装DirectAccess,但是我不断收到错误消息:

错误:无法从DirectAccess服务器GPO检索configuration设置。

我在网上search了一下,但是DirectAccess中并没有太多的信息(有些人提到安装很简单,有些人说远离它,因为这是一场噩梦),或者是这个错误消息。

这是截图:

在这里输入图像说明

这里是完整的安装日志:

Initializing operations before applying configuration Preparing to apply configuration changes... Backing up GPOs... Configuring Remote Access settings Retrieving server GPO details... Clearing existing stale configuration settings. This might take a few minutes... Checking the specified adapters... Deploying the Remote Access server behind NAT... Checking the network location server certificate... Checking the specified adapters... Checking for a native IPv6 deployment... Verifying the IP-HTTPS certificate... Generating a self-signed IP-HTTPS certificate on server DC1.example.local... Retrieving internal network DNS settings... Verifying the GPO to write settings... Creating the GPO. Linking the GPO to the domain... Checking for a client GPO to write settings... Creating the GPO. Linking the GPO to the domain... Checking for permissions to apply DirectAccess client policies to the GPO... Identifying all domains... Identifying infrastructure servers in domain example.local... Registering the DNS entry used to check client connectivity... Registering the web probe in DNS... Clearing existing stale configuration settings... Creating DirectAccess client policies... Updating client policies... Initializing accounting settings... Writing settings to the server GPOs... Writing settings to the client GPOs... Updating local settings... Applying GPOs on the Remote Access servers... Updating Network Connectivity Assistant settings Setting DirectAccess client settings in the client GPO... Finishing operations after applying configuration Finalizing configuration changes... Error: Configuration settings cannot be retrieved from the DirectAccess server GPO. Information: Attempting to roll back the configuration... 

在初始configuration期间你收到这个错误吗? 或者你正在更新现有的configuration?

如果您是第一次安装DirectAccess,如果您没有权限在Active Directory中创buildGPO,则会出现此消息。 解决这个问题的方法是让ADpipe理员创buildGPO并将其完全权限委托给您。

如果您正在更新现有configuration,则可能是DirectAccess客户端或服务器GPO缺失导致的。 确保GP中仍然存在GPO。 DirectAccess存在已知的GPO可能会被无意删除的问题(请参阅https://technet.microsoft.com/en-us/library/dn464274.aspx#Anchor_0 )。 如果是这种情况,您将不得不从备份还原GPO或删除并重新configurationDirectAccess。