Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG IPSEC Error - EST-P1: System did not accept any proposal received.

Hello,

Hopefully some one can help me. I am trying to setup a IPSEC VPN connection with the Sophos XG firewall. I have configured the IPSEC policy for remote access and also the l2tp server. I have setup the Windows 10 Built in VPN client to connect to the firewall, but whenever i connect i get the following error logged in the firewall:

EST-P1: System did not accept any proposal received. Need to reconfigure the connection on either ends

Below is a screenshot of my IPSEC policy settings. 

I have tried to authenticate using a local user account and also an Active Directory one. Below is my Windows 10 Client settings

I am trying to use IPSEC with a shared secret 



This thread was automatically locked due to age.
Parents Reply
  • Hi Oliver,

    Just confirming (as per the original note from Luk) you using an on appliance user and that you have configured both the L2TP Server and Connection Policy.

    - System > VPN > L2TP Settings

    - System > VPN > L2TP Connections

    Also change the authentication protocol at the console command line with "set vpn l2tp authentication any"

    (I went back and looked at your original screen shot and it appears to be the configuration for a full IPsec client and not the L2TP client, they are different settings)

Children
  • Hi Leon,

    I've managed to sort it. I didn't set up a l2tp connection.

    I'd setup a ipsec  connection and then the l2tp server. I thought the l2tp connection page was to list connected clients. I thought that the l2tp server would use the ipsec policy.

    Thanks for the help

    Regards

    Oliver Knights

  • I think I have all of my L2TP settings done.  I am trying to get my windows client to connect.

    I keep getting these "successful"  errors list here...  what could I be missing?

    I am using a local account on the firewall...

  • Hi John,

    The error "EST-P1: System did not accept an proposal received" is basically stating that Phase 1 negotiations failed as as there was a mismatch in protocols.

    Check out the following knowledge base articles

    As you are using Windows Client I suspect you may not have removed the Kerberos authentication method and possibly not set up the pre shared key on the Windows side.