L2TP errors from behind USG20-VPN
christopher
Posts: 1
Freshman Member
Freshman Member
Happy new year!
I am stumped on an issue I'm having with Android/iOS L2TP clients connecting to a Zywall USG20 from behind a USG20-VPN. The initial connections is connecting fine but after a few minutes to hours, the traffic will stop flowing on the L2TP session. When checking the USG20-Zywall log, there are a bunch of ipsec errors such as no policy found, dropping TCP/UDP/ESP/NAT-T packets. When checking the USG20-VPN log, it looks like it is responding to the IKE request without having any VPN's configured. I went down to the default config and still see ipsec messages in the log. When using a Windows 10 L2TP connections, there are no drops and works fine.
The traffic seams to stop right after the Zywall USG 20 sends a SEND HASH NOTIFY R U THERE. once that appears then the dropped packet message start rolling in with strange port number like 1024-1027.
When using a consumer router, no issues appear.
Diagram
Android Phone/tablet -----> Access Point ------> USG20-VPN ------>USG20-Zywall-----> LAN
I am stumped on an issue I'm having with Android/iOS L2TP clients connecting to a Zywall USG20 from behind a USG20-VPN. The initial connections is connecting fine but after a few minutes to hours, the traffic will stop flowing on the L2TP session. When checking the USG20-Zywall log, there are a bunch of ipsec errors such as no policy found, dropping TCP/UDP/ESP/NAT-T packets. When checking the USG20-VPN log, it looks like it is responding to the IKE request without having any VPN's configured. I went down to the default config and still see ipsec messages in the log. When using a Windows 10 L2TP connections, there are no drops and works fine.
The traffic seams to stop right after the Zywall USG 20 sends a SEND HASH NOTIFY R U THERE. once that appears then the dropped packet message start rolling in with strange port number like 1024-1027.
When using a consumer router, no issues appear.
Diagram
Android Phone/tablet -----> Access Point ------> USG20-VPN ------>USG20-Zywall-----> LAN
0
Comments
-
Hello christopher,
I want to confirm with you that in this scenario, the win10 can establish l2tp vpn with USG20, but Android/IOS cell phone have issue? If so, could you please check that can cell phone establish l2tp connection with public IP?(Cell phone connect with l2tp server directly)
Also, I want you check have you enable "NAT-T" in the USG ZyWALL's IPSec VPN Gateway setting.
Moreover, to analyze this case, when the issue occur, please screenshot complete log.
Charlie0
Categories
- All Categories
- 164 Beta Program
- 1.7K Nebula
- 86 Nebula Ideas
- 62 Nebula Status and Incidents
- 4.7K Security
- 236 Security Ideas
- 1.1K Switch
- 50 Switch Ideas
- 907 WirelessLAN
- 27 WLAN Ideas
- 5.3K Consumer Product
- 172 Service & License
- 294 News and Release
- 65 Security Advisories
- 14 Education Center
- 911 FAQ
- 399 Nebula FAQ
- 249 Security FAQ
- 90 Switch FAQ
- 100 WirelessLAN FAQ
- 18 Consumer Product FAQ
- 55 Service & License FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 68 About Community
- 51 Security Highlight
Zyxel Employee