Hello
I’m really hopeful an expert may be able to point me in the right direction. I’m fairly new to Mikrotik (moving from pfSense), and specifically installed an RB2011UAS to learn RouterOS.
I’m trying to do what should be really simple, and setup L2TP over IPSec for remote clients to dial-in to work.
Very simple small business setup -
Public IP - 82.70.xx.xxx
WAN on ether1, LAN on ether5
PPPoE client dials our VDSL connection…
Router - 10.0.0.254/24
Everything is NAT behind our public IP…
IP pool to VPN users is 10.0.1.1-20
Have spent hours reading guides and walk-throughs. I’ve followed the RoadWarrior guide line for line, i’ve read 10+ blogs/guides I can find - The simple fault at the moment is an OSX on home network client and iOS client over 4G - neither can connect, won’t even get past phase 1. It’s as if the server isn’t contactable.
- Enabled logging for IPSec and L2TP - nothing appears in logs.
- No packets show in the firewall entries for any of the 1701/500/4500 ports
- have disabled all firewall to no avail
- Have deleted and started again with configuration after configuration and not got any further.
Is there any chance somebody may be able to take a look at my config and point me in the right direction?
(for security i’ve masked domain and IP address)
Here’s a log from OSX when connecting:
Wed Jan 24 12:59:03 2018 : IPSec connection started
Wed Jan 24 12:59:03 2018 : IPSec phase 1 client started
Wed Jan 24 12:59:13 2018 : IPSec connection failed
Wed Jan 24 13:46:15 2018 : publish_entry SCDSet() failed: Success!
Wed Jan 24 13:46:15 2018 : publish_entry SCDSet() failed: Success!
Wed Jan 24 13:46:15 2018 : l2tp_get_router_address
Wed Jan 24 13:46:15 2018 : l2tp_get_router_address 192.168.0.1 from dict 1
Wed Jan 24 13:46:15 2018 : L2TP connecting to server ‘vpn.XXXXX.com’ (82.70.XX.XXX)…
Wed Jan 24 13:46:15 2018 : IPSec connection started
Wed Jan 24 13:46:15 2018 : IPSec phase 1 client started
Wed Jan 24 13:46:25 2018 : IPSec connection failed
Has anybody else experienced such a brick wall error right at the start? I’m on V6.41 RouterOS.
Any help would be grealty appreciated, and hapilly repaid with beer money!
Thanks
Ben