This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

PPTP/L2TP radius Authentication failing

Hello,

I am having an issue where VPN authentication is failing for all users when using radius as the authentication method. Local user authentication is working as long as the user in the user directory has not been created from Active Directory.

The radius server is granting access to the user authentication request, but the XG logs are denying the connection. This occurs for MS_CHAPv2 or PAP authentication requests.

I have tried with both console commands set vpn l2tp authentication MS_CHAPv2 and set vpn l2tp authentication ANY

     

Any suggestions are much appreciated.

Thankyou,
Derek



This thread was automatically locked due to age.
Parents
  • I have the excact same problem on XG310 SFOS16beta4.
    Did you ever find a solution to this?

    SSL VPN is working fine, and authenticating users against our AD.
    L2TP is working fine from Windows 7 built in VPN client with a local user on the XG.

    L2TP fails with the same client when trying to use the same AD user, that is working fine with SSL VPN.
    L2TP fails also if switching to Radius authentication. Even when the user tests OK in Radius server test.

    PAP, CHAP and CHAPv2 allways fails auth. (I have tried set vpn l2tp authentication ANY)

    Error is always excactly the same (Replace MS-CHAPv2 with CHAP / PAP respectively).
    System log: L2TP failed MS-CHAPv2: Authentication Failed for User xxx
    Authentication log: User xxx failed to login to L2TP through Local,AD,RADIUS authentication mechanism because of wrong credentials

    This happens with any combination of ways to input AD user (username, DOMAIN\username and username@DOMAIN - even though this last one is allready recognized on the XG box from logging on by Userportal and SSL VPN. (And YES, the user and AD group is of course added to L2TP list

Reply
  • I have the excact same problem on XG310 SFOS16beta4.
    Did you ever find a solution to this?

    SSL VPN is working fine, and authenticating users against our AD.
    L2TP is working fine from Windows 7 built in VPN client with a local user on the XG.

    L2TP fails with the same client when trying to use the same AD user, that is working fine with SSL VPN.
    L2TP fails also if switching to Radius authentication. Even when the user tests OK in Radius server test.

    PAP, CHAP and CHAPv2 allways fails auth. (I have tried set vpn l2tp authentication ANY)

    Error is always excactly the same (Replace MS-CHAPv2 with CHAP / PAP respectively).
    System log: L2TP failed MS-CHAPv2: Authentication Failed for User xxx
    Authentication log: User xxx failed to login to L2TP through Local,AD,RADIUS authentication mechanism because of wrong credentials

    This happens with any combination of ways to input AD user (username, DOMAIN\username and username@DOMAIN - even though this last one is allready recognized on the XG box from logging on by Userportal and SSL VPN. (And YES, the user and AD group is of course added to L2TP list

Children
No Data