When installing a gateway exit at a customer, turn on the L2TP service on one of the intranet servers (UGS5000 firewall), then map udp5000 ports, udp1701 ports, udp4500 ports on the egress gateways
Then the external network using the Windows system for L2TP dialing, has been prompted to dial failure, Wireshark caught the client in the dial-up to the server's udp500 port ISAKMP connection, the other server does not respond to the packet, the preliminary judgment is the firewall on the ACL policy guidance, Check the ACL configuration did not find the problem, after consulting the manual data found that windows in the L2TP dial the default use of certificate dialing, to L2TP dial failure, you need to modify the registry, as follows:
HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Services > Rasman > Parameters. In the right-hand side of the path, check if there is a key value with the name prohibitipsec and the data type DWORD. If it does not exist, right-click, select New > DWORD value and Name ProhibitIpSec, if this key value already exists, select the value, right-click, select Modify, and edit the DWORD value. In the Value data text box, fill in 1, and click OK.
Restart the PC for the changes to take effect.
After restarting the computer, dial again, success, Wireshark packet analysis, the computer after dialing directly to the UDP packet, and not to the server's UDP500 port to send ISAKMP data packets,
Note: This registry value is described below
windows2000/xp/2003 L2TP defaults to initiating IPSEC for certificate mode, so you must add ProhibitIpSec registry values to Windows to prevent the creation of automatic filters for l2tp/ipsec traffic.
ProhibitIpSec The registry value is set to 1 o'clock, Windows 2000-based computers do not create automatic filters that use CA authentication, but instead check for local IPSec policies or Active Directory IPSec policies.
to add the ProhibitIpSec registry value to Windows, follow these steps:
1. Click Start, click Run, type regedit, and then click OK.
2. Locate the following registry subkey, and then click it:
hkey_local_machine\system\currentcontrolset\services\rasman\parameters
3. Create a new DWORD value in this key.
4. Modify the value name to "ProhibitIpSec".
5. Double-click the value, modify value data to "1", and then click OK.
6. Quit Registry Editor, and then restart the computer.
L2TP dial failure, case resolution