This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP over IPsec remote access VPN

I am trying to setup VPN access to our lan for sales people, etc.  I have been able to successfully connect the L2tp tunnel, and it shows 2 green dots when I am connected, however the IPsec tunnel only shows active and never shows connected, and only a few Kb of traffic transit the firewall VPN to WAN rule.  No traffic transits the VPN to LAN or LAN to VPN firewall rules.  I am connecting with the native android client.  Below are my IPsec policy settings.  I am using the default L2TP policy for L2TP settings.

 

I am assuming that the IPsec status should show two green dots as well as the L2TP showing both green.  Is this correct?  What am I missing?



This thread was automatically locked due to age.
Parents Reply
  • I am configuring an L2TP/IPsec VPN tunnel.  

    I have it working now.

    My IPsec profile was fine.  I had a couple of mis-configurations on my firewall rules that were preventing traffic.

    I had set a primary gateway on my LAN-VPN rule that had to be removed, I had also configured NAT that had to be disabled, and finally, I had designated IP addresses for L2TP in the same range as my LAN, which was causing a conflicting virtual adapter to be created, so that had to be removed.  

     

    NONE of these issues were addressed in the article you linked and repeatedly insisted I read and follow, btw.  

    Since I haven't seen this well documented anywhere, here is how to COMPLETELY configure L2TP/IPsec VPN.

    The firewall rules you must have:

    I am using the built-in DefaultL2TP policy for both IPsec and L2TP connections.  The IPsec connection indicator never goes green, but the logs indicate a successful negotiation and hand off to L2TP.

Children
  • Hi.  I followed the steps for L2TP.  I also like to find out how to have L2TP/ IPsec setup.  What additional steps should be done?  What settings need to be ticked?  This is of course aside from the firewall rule you already posted.

    As I understand, the IPsec provides encryption to traffic that passes through, correct?