I've been banging my head against a wall over the past couple of days. Please tell me what is wrong with my setup?
As I see it, the client does not get any L2TP control responses from the server.
My configs:
ros code
/ip ipsec peer add exchange-mode=main-l2tp generate-policy=port-strict hash-algorithm=sha1 \ nat-traversal=yes secret=govno send-initial-contact=no /ppp profile add local-address=10.20.36.1 name=L2TP remote-address=l2tp use-encryption=no /ppp secret add name=user password=test profile=L2TP service=l2tp /interface l2tp-server server set authentication=chap default-profile=L2TP enabled=yes /ip firewall filter add chain=input comment=L2TP dst-port=4500 protocol=udp add chain=input comment=IPSEC protocol=ipsec-esp add chain=input comment=l2tp port=500 protocol=udp add chain=input comment=l2tp port=1701 protocol=udpHere's what client says in the logs:
Code: Select all
7/23/13 6:49:59.837 PM pppd[3419]: pppd 2.4.2 (Apple version 596.13) started by vitaly, uid 501
7/23/13 6:49:59.878 PM pppd[3419]: L2TP connecting to server '81.92.25.1' (81.92.25.1)...
7/23/13 6:49:59.881 PM pppd[3419]: IPSec connection started
7/23/13 6:49:59.906 PM racoon[3422]: Connecting.
7/23/13 6:49:59.906 PM racoon[3422]: IPSec Phase1 started (Initiated by me).
7/23/13 6:49:59.909 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 1).
7/23/13 6:49:59.929 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 2).
7/23/13 6:49:59.936 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 3).
7/23/13 6:49:59.982 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 4).
7/23/13 6:50:00.003 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Main-Mode message 5).
7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 AUTH: success. (Initiator, Main-Mode Message 6).
7/23/13 6:50:00.020 PM racoon[3422]: IKE Packet: receive success. (Initiator, Main-Mode message 6).
7/23/13 6:50:00.020 PM racoon[3422]: IKEv1 Phase1 Initiator: success. (Initiator, Main-Mode).
7/23/13 6:50:00.020 PM racoon[3422]: IPSec Phase1 established (Initiated by me).
7/23/13 6:50:00.000 PM kernel[0]: L2TP domain init
7/23/13 6:50:00.000 PM kernel[0]: L2TP domain init complete
7/23/13 6:50:01.022 PM racoon[3422]: IPSec Phase2 started (Initiated by me).
7/23/13 6:50:01.023 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 1).
7/23/13 6:50:01.047 PM racoon[3422]: IKE Packet: receive success. (Initiator, Quick-Mode message 2).
7/23/13 6:50:01.048 PM racoon[3422]: IKE Packet: transmit success. (Initiator, Quick-Mode message 3).
7/23/13 6:50:01.048 PM racoon[3422]: IKEv1 Phase2 Initiator: success. (Initiator, Quick-Mode).
7/23/13 6:50:01.049 PM racoon[3422]: IPSec Phase2 established (Initiated by me).
7/23/13 6:50:01.049 PM pppd[3419]: IPSec connection established
7/23/13 6:50:21.050 PM pppd[3419]: L2TP cannot connect to the server
7/23/13 6:50:21.052 PM racoon[3422]: IPSec disconnecting from server 81.92.25.1
7/23/13 6:50:21.053 PM racoon[3422]: IKE Packet: transmit success. (Information message).
7/23/13 6:50:21.054 PM racoon[3422]: IKEv1 Information-Notice: transmit success. (Delete IPSEC-SA).
7/23/13 6:50:21.054 PM racoon[3422]: IKE Packet: transmit success. (Information message).
7/23/13 6:50:21.055 PM racoon[3422]: IKEv1 Information-Notice: transmit success. (Delete ISAKMP-SA).
Code: Select all
18:55:08 l2tp,debug,packet rcvd control message from 81.92.23.13:62515
18:55:08 l2tp,debug,packet tunnel-id=0, session-id=0, ns=0, nr=0
18:55:08 l2tp,debug,packet (M) Message-Type=SCCRQ
18:55:08 l2tp,debug,packet (M) Protocol-Version=0x01:00
18:55:08 l2tp,debug,packet (M) Framing-Capabilities=0x3
18:55:08 l2tp,debug,packet (M) Host-Name=0x72:6f:62:6f:62:6f:6f:6b:00
18:55:08 l2tp,debug,packet (M) Assigned-Tunnel-ID=2
18:55:08 l2tp,debug,packet (M) Receive-Window-Size=4
18:55:08 l2tp,debug,packet sent control message (ack) to 81.92.23.13:62515
18:55:08 l2tp,debug,packet tunnel-id=2, session-id=0, ns=1, nr=1
18:55:10 l2tp,debug,packet sent control message to 81.92.23.13:62515
18:55:10 l2tp,debug,packet tunnel-id=2, session-id=0, ns=0, nr=1
18:55:10 l2tp,debug,packet (M) Message-Type=SCCRP
18:55:10 l2tp,debug,packet (M) Protocol-Version=0x01:00
18:55:10 l2tp,debug,packet (M) Framing-Capabilities=0x1
18:55:10 l2tp,debug,packet (M) Bearer-Capabilities=0x0
18:55:10 l2tp,debug,packet Firmware-Revision=0x1
18:55:10 l2tp,debug,packet (M) Host-Name="gw"
18:55:10 l2tp,debug,packet Vendor-Name="MikroTik"
18:55:10 l2tp,debug,packet (M) Assigned-Tunnel-ID=101
18:55:10 l2tp,debug,packet (M) Receive-Window-Size=4
18:55:12 l2tp,debug,packet rcvd control message from 81.92.23.13:62515
18:55:12 l2tp,debug,packet tunnel-id=0, session-id=0, ns=0, nr=0
18:55:12 l2tp,debug,packet (M) Message-Type=SCCRQ
18:55:12 l2tp,debug,packet (M) Protocol-Version=0x01:00
18:55:12 l2tp,debug,packet (M) Framing-Capabilities=0x3
18:55:12 l2tp,debug,packet (M) Host-Name=0x72:6f:62:6f:62:6f:6f:6b:00
18:55:12 l2tp,debug,packet (M) Assigned-Tunnel-ID=2
18:55:12 l2tp,debug,packet (M) Receive-Window-Size=4
18:55:12 l2tp,debug,packet sent control message (ack) to 81.92.23.13:62515
18:55:12 l2tp,debug,packet tunnel-id=2, session-id=0, ns=1, nr=1
18:55:12 l2tp,debug tunnel 101 received no replies, disconnecting
18:55:12 l2tp,debug tunnel 101 entering state: dead