Problem l2tp connect
Freshman Member
Good evening,
We have a Zyxel VPN 100 and the L2TP protocol enabled, which several users with Macs with their configurations use. Everything worked for a week now, but it no longer works without any changes. Can you tell us what the problem is based on the logs I've attached and how to fix it?
warn sessions-limit ACCESS BLOCKMaximum sessions per host (1000) was exceeded. [count=67]
619 2025-09-29 11:59:13 82.52.139.253:51381 192.168.100.2:500info ike IKE_LOGThe cookie pair is : 0x548ac67f509aff13 / 0x0000000000000000
620 2025-09-29 11:59:13 82.52.139.253:51381 192.168.100.2:500info ike IKE_LOGRecv Main Mode request from [82.52.139.253]
621 2025-09-29 11:59:13 82.52.139.253:51381 192.168.100.2:500info ike IKE_LOGThe cookie pair is : 0x0fd6ecf1b3cd7690 / 0x548ac67f509aff13
622 2025-09-29 11:59:13 82.52.139.253:51381 192.168.100.2:500info ike IKE_LOGRecv:[SA][VID][VID][VID][VID][VID][VID][VID][VID][VID][VID][VID][VID]
623 2025-09-29 11:59:13 82.52.139.253:51381 192.168.100.2:500info ike IKE_LOGRecv IKE sa: SA([0] protocol = IKE (1), AES CBC key len = 256, HMAC-SHA256 PRF, HMAC-SHA256-128, 2048 bit MODP, HMAC-SHA1 PRF, HMAC-SHA1-96, HMAC-MD5 PRF, HMAC-MD5-96, HMAC-SHA512 PRF, HMAC-SHA512-256, 1536 bit MODP, 1024 bit MODP, AES CBC key len = 128,
624 2025-09-29 11:59:13 192.168.100.2:500 82.52.139.253:51381info ike IKE_LOGThe cookie pair is : 0x548ac67f509aff13 / 0x0fd6ecf1b3cd7690 [count=3]
625 2025-09-29 11:59:13 192.168.100.2:500 82.52.139.253:51381info ike IKE_LOG[ID] : Tunnel [RemoteAccess_L2TP_Wiz] Local IP mismatch
All Replies
-
Disable session limit set in VPN connection local policy to IP 0.0.0.0
Do you have internet access out the WAN port?
0 -
The problem only occurs when using a VPN in L2TP mode. I have regular access to the network both when we're on-site at the company and when we connect remotely using SSL. Can you give me some guidance or schedule a Teams call to disable this limitation?
0 -
To disable session limit it be in config > policy control > session control set default session per host to 0
to set local policy to IP 0.0.0.0 go to config > VPN > IPSec VPN > in VPN connection look for the VPN and set like the following:
The USG looks to have WAN interface with a 192.168.100.2 IP has this always been the case?
0 -
It's already set to 0 as in the photo. That 100.2 address has always been like this, in fact, as I reported, it had worked until last Friday, suddenly it no longer allowed the connection to be made in I2TP.
0 -
Have you added any more VPN connections?
Is the L2TP VPN gateway set to Pre-Shared Key or Certificate? is Certificate IP or domain name and valid or self signed?
have you tried a reboot?
0 -
I have other connections in SSL mode, and they work fine with Windows clients.
The L2TP VPN gateway is set to pre-shared keys and properly configured on the PCs that need to connect, but it still fails. The domain issues internal certificates, but I don't think that's the problem, otherwise it would have caused the problem with SSL mode as well. However, I haven't tried rebooting the device since the last time I did, two-factor authentication didn't work. Isn't there a way to reboot just the required part (L2TP) via SSH?0 -
You can disable two-factor and reboot if you think its a problem
0 -
Could restarting the device solve the problem that l2tp suddenly stopped working?
0 -
Just seems odd that if you have not added or changed anything that it stopped working of course its not ideal that you might need to reboot and that would need looking into if it happen again but if a reboot don't fix it that would seem to mean something was changed.
0 -
Did your firewall behind NAT when it was working before?
Please share your configuration so I can help you better on this.
Zyxel Melen0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 200 Nebula Ideas
- 126 Nebula Status and Incidents
- 6.3K Security
- 498 USG FLEX H Series
- 323 Security Ideas
- 1.6K Switch
- 83 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.8K Consumer Product
- 286 Service & License
- 457 News and Release
- 89 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.3K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 96 Security Highlight
Guru Member
