I assume the users are not logging on the domain, that is why the Kerberos token is unavailable. At least with Cisco VPN there is a option to enable logging on the domain. You might have to implement something custom so that users are authenticated on the domain when they use VPN.
↧