L2TP Phase 2 proposal mismatch
I have problems to set up a L2TP over IPSec VPN on my ZyWALL310 VPN.
I used both the Quick Setup to configure the VPN and I configured it manually from scratch. Always with the same result. It seems that Phase 1 of the negotiation works fine, but the log ends with:
[Default_L2TP_VPN_Connection] Phase 2 proposal mismatch
[SA] No proposal chosen.
I've attached some pics of my config. Any ideas?
Thanks for your help!
Screenshot of log:
For the log message: "Phase 2 proposal mismatch" which could be the Algorithm on VPN connection mismatch.
Double check the Encryption and Authentication on the USG are match with VPN client's.0
Try changing your proposal to the following
Hi Peter, hi Charlie!
Thanks for your suggestions! In fact, is was a mixture of wrong proposals and user management. I had great help yesterday from Zyxel support, who found out that my proposals were slightly wrong.
Today, the tunnel is working perfectly. I am now trying to find out how to assign different User Groups to different Security Policies.
In the L2TP Config, I've set "Allowed Users" to L2TP-Group, which is my preconfigured group of allowed Users.
In the 2 Security Policies ("IPSec Outgoing to Any" and "IPSec to Device"), I've done the same: I've limited it to the L2TP-Group Users. But that causes trouble. The VPN is only set up when I set the Users to "any".
I now 'only' need to figure out how to configure that part.
Just curious that why you want to configure it
("IPSec Outgoing to Any" and "IPSec to Device")0
- 8.5K All Categories
- 1.6K Nebula
- 71 Nebula Ideas
- 57 Nebula Status and Incidents
- 4.5K Security
- 226 Security Ideas
- 983 Switch
- 46 Switch Ideas
- 878 WirelessLAN
- 22 WLAN Ideas
- 5.2K Consumer Product
- 157 Service & License
- 280 News and Release
- 98 Success Stories
- 59 Security Advisories
- 13 Education Center
- 580 FAQ
- 263 Nebula FAQ
- 160 Security FAQ
- 76 Switch FAQ
- 74 WirelessLAN FAQ
- 7 Consumer Product FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 69 About Community
- 46 Security Highlight