Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP radius authentication failing XG210 (SFOS 16.01.1)

Hi, hoping someone can help assist with getting our L2TP VPN working with our RADIUS server.

Running an XG210 on SFOS 16.01.1

Experiencing same issue as this thread: https://community.sophos.com/products/xg-firewall/f/vpn/77206/pptp-l2tp-radius-authentication-failing

 

- Local user authentication works fine for L2TP

- RADIUS server is setup. Using "Test Connection" is successful with the user i'm trying to VPN in as.

- able to login to the admin portal using RADIUS with same user.

- RADIUS server selected as L2TP authentication method

- using preshared key for L2TP

- RADIUS server is running on our AD server, using AD as the authentication backend

network policy rules set up for LAN/VPN, VPN/LAN and VPN/WAN

 

Currently the only client I have access to is my iPhone 6 running iOS 9.3.3

Logs:

 

2016-10-26 09:23:12
L2TP
SUCCESSFUL
-
LCP : Negotiation Closed for 166.xxx.xx.45
17990
2016-10-26 09:23:06
IPsec
SUCCESSFUL
-
"GavantL2TP" SA-MGT: Deleting connection instance with peer 166.xxx.xx.45, isakmp=0, ipsec=0
17881
2016-10-26 09:23:06
IPsec
SUCCESSFUL
-
GavantL2TP SA-MGT: Peer requested to delete Phase-1 SA. Deleting ISAKMP state 154
17878
2016-10-26 09:23:06
IPsec
TERMINATED
-
IPSec Connection GavantL2TP between 208.xxx.xxx.146 and 166.xxx.xx.45 terminated.
17802
2016-10-26 09:23:06
IPsec
SUCCESSFUL
-
GavantL2TP SA-MGT: Peer requested to delete Phase-2 SA. Deleting IPSEC state 155
17879
2016-10-26 09:23:06
L2TP
FAILED
-
LCP : Negotiation Closing for 166.xxx.xx.45 : Authentication failed
17991
2016-10-26 09:23:06
L2TP
FAILED
-
IPCP : Taking IPCP down for 166.xxx.xx.45 : LCP down
17991
2016-10-26 09:23:06
L2TP
FAILED
-
CHAP : Authentication Failed for User chostetter
17986
2016-10-26 09:23:06
L2TP
SUCCESSFUL
-
CHAP : Starting Authentication
17984
2016-10-26 09:23:06
L2TP
SUCCESSFUL
-
LCP : Link Established for 166.xxx.xx.45
17983
2016-10-26 09:23:06
L2TP
SUCCESSFUL
-
LCP : Negotiation Opening for 166.xxx.xx.45
17982
2016-10-26 09:23:04
IPsec
SUCCESSFUL
-
"GavantL2TP" DPD: Dead peer detection enabled
17892
2016-10-26 09:23:04
IPsec
ESTABLISHED
-
IPSec Connection GavantL2TP between 208.xxx.xxx.146 and 166.xxx.xx.45 established.
17801
2016-10-26 09:23:04
IPsec
SUCCESSFUL
-
GavantL2TP EST-P2: Responding to a Phase-2 establishment request with message id a895ecb1
17867
2016-10-26 09:23:03
IPsec
SUCCESSFUL
-
"GavantL2TP" DPD: Dead peer detection enabled
17892
2016-10-26 09:23:03
IPsec
SUCCESSFUL
-
"GavantL2TP" SA-MGT: Deleting connection instance with peer 166.xxx.xx.45, isakmp=0, ipsec=0
17881
2016-10-26 09:23:03
IPsec
SUCCESSFUL
-
GavantL2TP EST-P1: Switched the connection from GavantL2TP to GavantL2TP. As GavantL2TP configuration matches the reqest better
17852
2016-10-26 09:23:03
IPsec
SUCCESSFUL
-
GavantL2TP EST-P1-MM peer id is ID_IPV4_ADDR: '10.xx.xx.62'
17848
2016-10-26 09:23:03
IPsec
SUCCESSFUL
-
EST-P1: Peer did not accept any proposal sent
17853
2016-10-26 09:23:03
IPsec
SUCCESSFUL
-
NAT-T: Remote Server is behind NAT device
17876

 

 

Any help or troubleshooting tips would be super appreciated. Thanks!



This thread was automatically locked due to age.
Parents
  • Hi Curt, 

    Navigate to Authentication > Service > VPN, order the Radius server object on the TOP here.

    Take SSH to XG and go to option  4. Device console. Execute, set vpn l2tp authentication ANY.

    Verify the configurations for the L2TP network adapter settings on the system. PFA screenshots:

    Make sure the preshared key is defined in the Advance settings.

    Thanks

Reply
  • Hi Curt, 

    Navigate to Authentication > Service > VPN, order the Radius server object on the TOP here.

    Take SSH to XG and go to option  4. Device console. Execute, set vpn l2tp authentication ANY.

    Verify the configurations for the L2TP network adapter settings on the system. PFA screenshots:

    Make sure the preshared key is defined in the Advance settings.

    Thanks

Children
No Data