L2TP VPN Active Directory authentication do not work

Options
Sébastien
Sébastien Posts: 41  Freshman Member
First Anniversary 10 Comments Friend Collector
Hi everyone,

I'm trying to set up an L2TP/IPSec VPN with AD authentication but it does not work because my user is rejected. The appliance is a USG Flex 100 managed by Nebula.

First of all, I add my AD to Nebula


And I configure the VPN server with my AD for authentication

Then I add a test user to my AD users


And finally, here is the log when trying to connect to this VPN


It's really surprising because I'm 200% hundred sure of the username and password.

Am i doing something wrong ? Please also note that the USG Flex is correctly added to my AD in the "Computers" section.

Should I configure something else on my AD ? NPS maybe ? Or should the user be added to a specific group ?

Thanks,

Sebastien

All Replies

  • Zyxel_James
    Zyxel_James Posts: 616  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Please confirm the account could be queried by your firewall. Connect to console port and input
    "_debug domain-auth test profile-name example.profile.name username example.username password example.password".

    Moreover, please provide org/site to me via private message, and enable Zyxel support access, you can find it at Help > Support Request > Zyxel support access, enable zyxel support. I would like to check on your device, thank you.

    James

  • Sébastien
    Sébastien Posts: 41  Freshman Member
    First Anniversary 10 Comments Friend Collector
    Options
    Dear James,

    I have tried the command using a SSH connection to the router, and the answer is :

    % Get AD group VDC has failed
    retval = -24004
    ERROR: Display AAA group has failed.

    Where VDC is the name of my AD configuration in Nebula.

    What does this mean ?

    Thanks,

    Sébastien
  • Zyxel_James
    Zyxel_James Posts: 616  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    Hi @Sébastien, I have contacted you via PM, please check your inbox, thank you.
    James

Nebula Tips & Tricks