NAT-T & IPSec Issues still exist

I can confirm that L2TP+IPSEC+PSK+NAT-T+ ROS 5.14 works just fine for me from my laptop running MacOS 10.6.8.

I’ve been having some problems with a new Android 2.3 phone, but that appear to be a function of the carrier, and I haven’t tried via wifi instead of 3g.

Note that for Windows XP and possibly other Windows versions, you have to configure the registry to allow NAT-T, then set up main-l2tp at the Mikrotik end.

Wow, good work guys, i can confirm L2TP/IPSec now working for me, from Windows 7 behind NAT and from Iphone behind NAT (ROS 5.14). I would later test connection from Android 2.3 phone.

I can also confirm that L2TP+IPSEC+PSK+NAT-T+ ROS 5.14 works with windows registry modification and main-l2tp peer setting.
What about certificates instead of PSK?

Could one of you post a config pls? I’m still having a problem with it. I’m getting an error “invalid length of payload”

No matter what I try I cannot get two users from behind the same NAT to connect to my LTP/IPSEC Mik even with NAT-T enabled. Firmware 5.19. Can anyone else confirm this?

Somewhat uninformed speculation:

I think this is because you can’t “Generate” unique policies - I could well be wrong - but I think that’s the problem.
Not confirming, but I may well be testing it myself. I’ll try to update if I find out something helpful/definitive.

It would be great if you’d update with anything you find.

-Greg