This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SophosXG Firewall L2TP VPN Connection Problems

Hi,

i have upgraded my sg210 firewall from utm to sophos xg. On the utm i have configured an l2tp vpn connection with radius authentication and it works fine. The sophos xg its new for me, but i think i do the right things (i hope so). I have add the radius and ad server and and the test´s works fine. Then i have set up the vpn group over the import button and create a l2tp connection with a shared secret and with the same details then the sophos utm have. Then i will test the vpn connection and i configured my iphone for an l2tp connection. In the sophos xg authentication log i see the following:

"User testuser failed to login to L2TP through RADIUS authentication mechanism because of wrong credentials."

But the radius connection test is successful and i can login into the user portal with the same credentials.

What i have already done:

- compare the shared secret -> its the same
- check if the login credentials are correct -> passed
- check if the l2tp connection is activ -> passed

Does anyone an idea what else i can check? The error message from the sophos log is a bit irritating.

Here are some configuration screenshots...


Thanks and greetings
Christian



This thread was automatically locked due to age.
Parents
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    Could you please provide access_server logs in debugging? 

    Run the following command from the advanced shell to put the access_server in debug: service access_server:debug -ds nocync 

    Note: Run the same command to remove the service from the debug. 

    Did you set Simultaneous logins limit for the users? You can check this under Authentication > Users > Open the user detail or under Authentication > Services Global Settings. 

    Did you configure the leasing an IP address from the RADIUS server? You can see this option under VPN > VPN Settings > L2TP.

    Thanks,

Reply
  • FormerMember
    0 FormerMember

    Hi ,

    Thank you for reaching out to the Community! 

    Could you please provide access_server logs in debugging? 

    Run the following command from the advanced shell to put the access_server in debug: service access_server:debug -ds nocync 

    Note: Run the same command to remove the service from the debug. 

    Did you set Simultaneous logins limit for the users? You can check this under Authentication > Users > Open the user detail or under Authentication > Services Global Settings. 

    Did you configure the leasing an IP address from the RADIUS server? You can see this option under VPN > VPN Settings > L2TP.

    Thanks,

Children
No Data