Community discussions

MikroTik App
 
chiefbmr
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 51
Joined: Sat Jul 17, 2004 6:22 pm
Location: USA

L2TP/IPsec VPN server to Windows Client

Mon Nov 29, 2021 2:39 am

I use to run a PPTP vpn server but now switched to L2TP/IPsec server.

Setup like Wiki and other examples have explained. Android clients work fine. Windows clients can't connect. Is there something simple I am missing. I have played around with various security settings on server with no luck. Tried several different windows PCs with no luck.
 
User avatar
MickeyT
Member Candidate
Member Candidate
Posts: 125
Joined: Tue Feb 18, 2020 7:06 am
Location: Australia

Re: L2TP/IPsec VPN server to Windows Client

Mon Nov 29, 2021 8:07 am

Are you using the L2TP VPN server in RouterOS?

If you have the VPN server running on a Windows Server behind the MikroTik (i.e.: All traffic forwarded through the MikroTik) then you need to make a registry entry change on all Windows VPN clients. See this MS page for instructions on making the necessary change (Don't worry about MS referring to Server 2003 and Server 2008, it applies to all Server versions and Windows clients). This problem only applies to Windows clients as Linux, Apple and Android clients can resolve the issue automatically.
 
chiefbmr
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 51
Joined: Sat Jul 17, 2004 6:22 pm
Location: USA

Re: L2TP/IPsec VPN server to Windows Client

Mon Nov 29, 2021 7:15 pm

Are you using the L2TP VPN server in RouterOS?
Sorry, Yes I am using the VPN server in RouterOS.
Thanks
 
User avatar
MickeyT
Member Candidate
Member Candidate
Posts: 125
Joined: Tue Feb 18, 2020 7:06 am
Location: Australia

Re: L2TP/IPsec VPN server to Windows Client

Tue Nov 30, 2021 11:52 am

OK, you shouldn't need to make the registry change because of your MikroTik configuration but, since it doesn't hurt to do it, I'd recommend you try making the change on a test Windows client to see if it helps resolve the problem (Your clients might be going through a NAT they don't know about).

Personally I make the change regardless of where the Windows client is being used and set the AssumeUDPEncapsulationContextOnSendRule value to 2. Doing this allows Windows to determine what (if any) UDP encapsulation is required and also eliminates a potential problem that could crop up later on.
 
mikruser
Long time Member
Long time Member
Posts: 578
Joined: Wed Jan 16, 2013 6:28 pm

Re: L2TP/IPsec VPN server to Windows Client

Tue Nov 30, 2021 12:52 pm

I have played around with various security settings on server with no luck.
create ipsec proposal sha1/aes-128 cbc and profile with DH Group: ecp256

Who is online

Users browsing this forum: No registered users and 43 guests