The NPS logs are not showing any errors, Reason-Code always returns 0 for both remote sites and HQ. That being said, the failing connections are never getting an Access-Reject packet.
For the remote sites, we are seeing the Access-Request and Access-Challenge packets followed by an Access-Accept. For HQ, We are only seeing Access-Requests and Access-Challenges over and over, but never an Access-Reject. When we look in event logs, we can see successful connections from remote sites, but never the failed attempts from HQ. We only see those in the NPS logs.
At one point, we made a change to the MTU just to see if clients are seeing the change. We can see the MTU change reflected in the logs from remote sites, but not from HQ.
Here's a success from remote site
![JTTech_0-1691084954160.png JTTech_0-1691084954160.png](https://community.meraki.com/t5/image/serverpage/image-id/31692iEED2E5F2797BF03F/image-size/medium?v=v2&px=400)
![JTTech_1-1691084975565.png JTTech_1-1691084975565.png](https://community.meraki.com/t5/image/serverpage/image-id/31693i9BCB00BA0281311D/image-size/medium?v=v2&px=400)
![JTTech_2-1691084993651.png JTTech_2-1691084993651.png](https://community.meraki.com/t5/image/serverpage/image-id/31694i93E45598D019752B/image-size/medium?v=v2&px=400)
Here's a failure from HQ (over and over until a timeout I assume)
![JTTech_3-1691085061243.png JTTech_3-1691085061243.png](https://community.meraki.com/t5/image/serverpage/image-id/31695i4A001444A40AC114/image-size/medium?v=v2&px=400)
![JTTech_4-1691085077998.png JTTech_4-1691085077998.png](https://community.meraki.com/t5/image/serverpage/image-id/31696iC0E47E959F4117EA/image-size/medium?v=v2&px=400)
![JTTech_5-1691085118518.png JTTech_5-1691085118518.png](https://community.meraki.com/t5/image/serverpage/image-id/31697i0E230B06DA3CF88A/image-size/medium?v=v2&px=400)
![JTTech_6-1691085143647.png JTTech_6-1691085143647.png](https://community.meraki.com/t5/image/serverpage/image-id/31698i040980D71FDE182C/image-size/medium?v=v2&px=400)