Login fails - L2TP VPN Client Server between ZyWALL USG 100 and Windows 10
Have configured ZyWall USG 100 for L2TP VPN Client-Server as per Zyxel documentation. As per log below all works up to the point of ready to pass VPN username and password, at which point it disconnects. No NAT connected router on the WAN side of ZyWall.
Then we receive this message:
"The network connection between your computer and the VPN server could not be established because the remote server is not responding. This could be because one of the network devices (e.g., firewalls, NAT, Router etc.) between your computer and the remote server is not configured to allow VPN connections. Please contact your Administrator or your service provider to determine which device may be causing the problem."
Log:
No. Date/Time Source Destination
Anyone have an idea of what the fault could be causing disconnection before authenticating VPN username and password?
Cheers,
Dale.
Comments
-
Line 28 onwards of log above seems to be where the disconnection happens for our VPN client-server login.
Do you have any suggestions Charlie? I can certainly send you the firewall config if required to help troubleshoot.0 -
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Hi Emily,
Minutes after I received your post reply I resolved the L2TP VPN client to site login failure. Let me explain more ...
We have in place of course the Default Firewall rule for WAN to ZyWALL for IKE, ESP, NATT and also added USP 1701 - login failed under these conditions as stated in my original post.
We added a new Firewall rule yesterday that allowed login - found this tip here http://www.iholken.com/index.php/2015/07/19/setup-vpn-l2tpipsec-tunnel-between-zywall-usg-and-windows-phone-8-1-or-iphoneipad/ . Could not find any reference to this rule being required in the ZyXel guides.
Once the L2TP VPN login worked we then found we could not contact any internal IP addresses on the LAN we connected to. So we had to add this route, again from "iholken's" steps:
Is there a ZyXel document for setting up L2TP VPN Client to Site that details these requirements. Or for some reason is our USG 100 setup somehow unique - I wouldn't have thought so as that "iholken's" article has helped many.
Regards,
Dale.0 -
Forgot to mention we also needed to add this Firewall rule to enable contact to internal addresses on LAN:
0 -
Hi @AWUSupport,
You don't need to add extra firewall rules for L2TP clients.
Just configure Default_L2TP_VPN_GW, Default_L2TP_VPN_Connection and L2TP VPN like the following example.
Default_L2TP_VPN_GW
Default_L2TP_VPN_Connection
The local policy is the wan IP address.
L2TP VPN
Assign a pool for L2TP clients. Note that the pool cannot conflict with any other existing subnet even if they are not in use.
Firewall
Use the default firewall rules.
On Windows 10, set the default protocol the setting and select PAP only.
Result
L2TP clients are connected successfully.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 151 Nebula Ideas
- 98 Nebula Status and Incidents
- 5.7K Security
- 277 USG FLEX H Series
- 277 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.4K Consumer Product
- 250 Service & License
- 395 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 75 Security Highlight