L2TP dial failure, case resolution

Source: Internet
Author: User

When installing a gateway exit at a customer, turn on the L2TP service on one of the intranet servers (UGS5000 firewall), then map udp5000 ports, udp1701 ports, udp4500 ports on the egress gateways

Then the external network using the Windows system for L2TP dialing, has been prompted to dial failure, Wireshark caught the client in the dial-up to the server's udp500 port ISAKMP connection, the other server does not respond to the packet, the preliminary judgment is the firewall on the ACL policy guidance, Check the ACL configuration did not find the problem, after consulting the manual data found that windows in the L2TP dial the default use of certificate dialing, to L2TP dial failure, you need to modify the registry, as follows:

HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Services > Rasman > Parameters. In the right-hand side of the path, check if there is a key value with the name prohibitipsec and the data type DWORD. If it does not exist, right-click, select New > DWORD value and Name ProhibitIpSec, if this key value already exists, select the value, right-click, select Modify, and edit the DWORD value. In the Value data text box, fill in 1, and click OK.
Restart the PC for the changes to take effect.

After restarting the computer, dial again, success, Wireshark packet analysis, the computer after dialing directly to the UDP packet, and not to the server's UDP500 port to send ISAKMP data packets,


Note: This registry value is described below

windows2000/xp/2003 L2TP defaults to initiating IPSEC for certificate mode, so you must add ProhibitIpSec registry values to Windows to prevent the creation of automatic filters for l2tp/ipsec traffic.
ProhibitIpSec The registry value is set to 1 o'clock, Windows 2000-based computers do not create automatic filters that use CA authentication, but instead check for local IPSec policies or Active Directory IPSec policies.
to add the ProhibitIpSec registry value to Windows, follow these steps:
1. Click Start, click Run, type regedit, and then click OK.
2. Locate the following registry subkey, and then click it:
hkey_local_machine\system\currentcontrolset\services\rasman\parameters
3. Create a new DWORD value in this key.
4. Modify the value name to "ProhibitIpSec".
5. Double-click the value, modify value data to "1", and then click OK.
6. Quit Registry Editor, and then restart the computer.

L2TP dial failure, case resolution

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.