Is the USG20 L2TP behind NAT compatible ?

virtuOS
virtuOS Posts: 11
First Comment Friend Collector
edited April 2021 in Security
Hello everybody,

I try to configure my USG20 L2TP behind a Nat but it's not working. 

I follow this guides but without success... : How to configure L2TP behind NAT – Zyxel Support Campus EMEA and USG 110 L2TP VPN behind companion nat firewall — Zyxel

Did someone know if that's a compatibility problem like they said on VPN server behind NAT router - configuration problems — Zyxel ?

Thanks in advance for your help.

Best regards

Accepted Solution

  • Zyxel_Can
    Zyxel_Can Posts: 342  Zyxel Employee
    25 Answers First Comment Friend Collector
    Answer ✓

    Hi @mri @virtuOS

     

    USG20-VPN or USG20W-VPN series with ZLD4.30 or above version could be a L2TP server behind NAT router.

    USG20 latest version is 3.30(BDQ.9). It’s not compatible with L2TP behind NAT.

    You may consider upgrade your device to USG FLEX 100 or ATP100 series.


    Best regards.


All Replies

  • Zyxel_Can
    Zyxel_Can Posts: 342  Zyxel Employee
    25 Answers First Comment Friend Collector
    Hi @virtuOS,

    Can you please share some information;

    1- What's the device model's full name and full name of firmware version?

    2- Where did you fail in the configuration?

    3- Had you configured the related port forwarding settings on the gateway in front of USG20?

    4- If you mean that you couldn't manage to configure L2TP due to there's no VPN Settings for L2TP VPN Settings option in the VPN Setup Wizard, can you please try to configure your L2TP manually as in the following article?

     

    https://kb.zyxel.com/KB/searchArticle!viewBlob.action?attOid=14517

    Best regards.
  • virtuOS
    virtuOS Posts: 11
    First Comment Friend Collector
    Hi Zyxel_Can,

    Thanks for your interest.

    Here are the reponses you ask for:

    1- What's the device model's full name and full name of firmware version?

    Model name : ZyWALL USG 20
    Firmware version : 3.30(BDQ.9) / 1.17 / 2016-11-22 09:50:31

    2- Where did you fail in the configuration?

    The l2tp vpn  can not connected on client computers. I receive an error in the logs :

    [SA] : No proposal chosen
    [SA] : Tunnel [Felix_FLV] Phase 1 proposal mismatch

    3- Had you configured the related port forwarding settings on the gateway in front of USG20?

    Yes. All is forwarded to the USG20

    4- If you mean that you couldn't manage to configure L2TP due to there's no VPN Settings for L2TP VPN Settings option in the VPN Setup Wizard, can you please try to configure your L2TP manually as in the following article?

    That's what i did but without success....


    Thank in advance for your help :-)

  • Zyxel_Can
    Zyxel_Can Posts: 342  Zyxel Employee
    25 Answers First Comment Friend Collector
    edited March 2021

    Hi @virtuOS,

     

    Unfortunately your ZyWALL USG 20 is not compatible for L2TP Behind NAT.

     

    Please consider to replace your device with new model. (e.g. USG FLEX 100)

     

    Best regards.
  • mri
    mri Posts: 1
    First Comment Friend Collector
    Hi @virtuOS,

    It's possible to configure an USG20 L2TP behind a Nat. I did it this week.

    I recommend that you go through the zyxel setup wizard and then desactivate the ADP security (or customize it according to your needs but L2TP traffic tends to be blocked). For the NAT rule, configure it as a Virtual Server.
  • Zyxel_Can
    Zyxel_Can Posts: 342  Zyxel Employee
    25 Answers First Comment Friend Collector
    Answer ✓

    Hi @mri @virtuOS

     

    USG20-VPN or USG20W-VPN series with ZLD4.30 or above version could be a L2TP server behind NAT router.

    USG20 latest version is 3.30(BDQ.9). It’s not compatible with L2TP behind NAT.

    You may consider upgrade your device to USG FLEX 100 or ATP100 series.


    Best regards.


Security Highlight