I am trying to setup a L2TP\IPSec Client to gateway VPN. Ive combed the forms and have been Googling solutions for almost 48 hours straight without any luck. So I figured I post this thread and see if any wisdom comes my way.
I have comcast business class internet with 2 static IPs. I'll call them sIP1 and sIP2. The network diagram is as follows:
Gateway has sIP1 as it's wan address and forwards traffic to an internal router 192.168.0.1 through a NAT.
DSR-250 is plugged into the Gateway with sIP2 set as a static wan address, with a comcast subnet, and comcast gateway. The DSR-250 is not behind a NAT.
Comcast Gateway
Cisco DPC3939B hardware revision 1.0
DSR-250 firmware 2.11_ww
DSR Configuration
My IPSec Policy:
Name: IPSecVPN
Policy Type: IPv4
IKE Version: IKEv1
L2TP Mode: Client
IPSec Mode: Transport
Select Local Gateway: Dedicated Wan
Mode Config: off
Rollover: off
Protocol: ESP
Keepalive: off
Phase 1 (IKE SA Parameters)
Exchange Mode: Aggressive
Direction: Responder
Nat-T: on
Nat keep alive freq: 20
Local Identifier Type: FQDN
Local Identifier: 192.168.0.0
Remote Identifier: FQDN
Remote Identifier: 0.0.0.0
Encryption Algorithm: AES-128, AES-256, 3DES
Authentication Algorithm: MD5, SHA-1, SHA-256
Authentication Method: Pre-shared Key
Pre-Shared key: reallyStrongKey
DH Group: Group 2
SA-Lifetime: 28800
Dead Peer: ON
Detection Period: 20
Reconnect after failure: 5
Extended Authentication: None
Phase 2(Auto Policy)
SA lifetime 3600 seconds
Encryption Algorithm 3DES, AES-128, AES-256
Integrity Algorithm MD5, SHA-1, SHA-256
PFS Key Group: off
My L2TP Server settings
Enable L2TP Server: Enable IPv4
L2TP Routing Mode: NAT
Starting IP: 192.168.0.50
Ending IP: 192.168.0.65
Authentication: Local User Database
CHAP, MS-Chap, MS-Chapv2 ON
Secret Key: off
User timeout 800
User Group
name (VPN)
has L2TP and XAuth enabled
set to network level
I have one user that uses the user group VPN
I'm trying to connect to the VPN from an Android device. When I attempt to connect from my device to sIP2 I can see in the DSR-250 VPN Logs:>
Error IPSEC [Identity Protection mode of (invalid)[invalid] is not acceptable
VPN INFORMATION IPSEC Anonymous configuration selected for <mobile device ip>[27082]
Those 2 errors just repeat and then the connection is dropped.
Android VPN Config:
Name: VPN
TYpe: L2TP/IPSEC PSK
Server: sIP2
L2TP secret: not used
IPSec identifier: not used
IPSec pre-shared key: reallyStrongKey
This is a requirement to use L2TP\IPSEC I cannot use OpenVPN or SSLVPN. The remote clients do not have static ips and the DSR-250 has to accept all incoming remote ips and will verify them using the local database and pre-shared key.
Any support would be appreciated.
Updates:
From the comcast gateway I disabled port management and allowed all traffic through. I am now seeing the following:
[Thu Oct 6 16:37:59 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: the packet retransmitted in a short time from 73.81.117.158[27034]]
[Thu Oct 6 16:37:59 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: The packet is retransmitted by 73.81.117.158[27034].]
[Thu Oct 6 16:38:00 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Phase 1 negotiation failed due to time up for 73.81.117.158[27034]. b88a126f74258911:8a0325f0af6a6c3a]
[Thu Oct 6 16:35:07 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Anonymous configuration selected for 73.81.117.158[27034].]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Received request for new phase 1 negotiation: <sIP2>[500]<=>73.81.117.158[27034]]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Beginning Aggressive mode.]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Received unknown Vendor ID]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Received Vendor ID: RFC 3947]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Received unknown Vendor ID]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Received Vendor ID: draft-ietf-ipsec-nat-t-ike-02]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Received unknown Vendor ID]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: Received Vendor ID: DPD]
[Thu Oct 6 16:35:08 2016(GMT-0500)] [DSR-250] [2.11] [VPN] [Information] [IPSEC] [IKE: For 73.81.117.158[27034], Selected NAT-T version: RFC 394]