DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
SOLVED: Vigor 2762 L2TP/IPsec from SmartVPN - timeout errors
- ndp
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
- Thank you received: 0
25 Jun 2020 07:44 #96500
by ndp
SOLVED: Vigor 2762 L2TP/IPsec from SmartVPN - timeout errors was created by ndp
I am trying to connect L2TP/IPsec VPN to my Vigor 2762 from Draytek SmartVPN Client on Windows10 , but I repeatedly get L2TP IKE link timeout errors.
In the copy of the log output below, I have replaced the client Wan IP with xx.xxx.xxx.xxx and the Wan IP of the 2762 with yy.yy.yyy.yyy for security reasons.
In the actual log output, the both the above mentioned IP addressess are recorded correctly.
Also, I can connect successfully via SSL VPN and PPTP VPN from the same SmartVPN client.
###
Jun 25 07:28:10 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: Responding to Main Mode from xx.xxx.xxx.xxx
Jun 25 07:28:10 draytek01 draytek01: Matching General Setup key for dynamic ip client...
Jun 25 07:28:10 draytek01 draytek01: Accept Phase1 proposals : ENCR OAKLEY_AES_CBC, HASH OAKLEY_SHA
Jun 25 07:28:10 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_KE, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: NAT-Traversal: Using RFC 3947, peer is NATed
Jun 25 07:28:10 draytek01 draytek01: Matching General Setup key for dynamic ip client...
Jun 25 07:28:10 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_KE, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_ID, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_ID, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: #401 sent MR3, ISAKMP SA established with xx.xxx.xxx.xxx. In/Out Index: 34/0
Jun 25 07:28:11 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_HASH, Exchange Type = 0x20, Message ID = 0x1
Jun 25 07:28:11 draytek01 draytek01: Receive client L2L remote network setting is yy.yy.yyy.yyy/32
Jun 25 07:28:11 draytek01 draytek01: [IPSEC/IKE][Local][34:-][@xx.xxx.xxx.xxx] quick_inI1_outR1: match network
Jun 25 07:28:11 draytek01 draytek01: Accept ESP proposal ENCR ESP_AES, HASH AUTH_ALGORITHM_HMAC_SHA1
Jun 25 07:28:11 draytek01 draytek01: Responding to Quick Mode from xx.xxx.xxx.xxx
Jun 25 07:28:11 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_HASH, Exchange Type = 0x20, Message ID = 0x1
Jun 25 07:28:11 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_HASH, Exchange Type = 0x20, Message ID = 0x1
Jun 25 07:28:11 draytek01 draytek01: IPsec SA #402 will be replaced after 2850 seconds
Jun 25 07:28:11 draytek01 draytek01: #402 IPsec SA established with xx.xxx.xxx.xxx. In/Out Index: 34/0
Jun 25 07:28:23 draytek01 draytek01: [L2TP][@0.0.0.0] IKE link timeout: state wait_L2
Jun 25 07:28:23 draytek01 draytek01: [L2TP][@0.0.0.0] pppShutdown
###
Firmware Version: 3.9.2_BT
SmartVPN 5.3.1
If anyone knows of a solution to these L2TP IKE link timeout errors , It would be greatly appreciated.
In the copy of the log output below, I have replaced the client Wan IP with xx.xxx.xxx.xxx and the Wan IP of the 2762 with yy.yy.yyy.yyy for security reasons.
In the actual log output, the both the above mentioned IP addressess are recorded correctly.
Also, I can connect successfully via SSL VPN and PPTP VPN from the same SmartVPN client.
###
Jun 25 07:28:10 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: Responding to Main Mode from xx.xxx.xxx.xxx
Jun 25 07:28:10 draytek01 draytek01: Matching General Setup key for dynamic ip client...
Jun 25 07:28:10 draytek01 draytek01: Accept Phase1 proposals : ENCR OAKLEY_AES_CBC, HASH OAKLEY_SHA
Jun 25 07:28:10 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_SA, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_KE, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: NAT-Traversal: Using RFC 3947, peer is NATed
Jun 25 07:28:10 draytek01 draytek01: Matching General Setup key for dynamic ip client...
Jun 25 07:28:10 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_KE, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_ID, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_ID, Exchange Type = 0x2, Message ID = 0x0
Jun 25 07:28:10 draytek01 draytek01: #401 sent MR3, ISAKMP SA established with xx.xxx.xxx.xxx. In/Out Index: 34/0
Jun 25 07:28:11 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_HASH, Exchange Type = 0x20, Message ID = 0x1
Jun 25 07:28:11 draytek01 draytek01: Receive client L2L remote network setting is yy.yy.yyy.yyy/32
Jun 25 07:28:11 draytek01 draytek01: [IPSEC/IKE][Local][34:-][@xx.xxx.xxx.xxx] quick_inI1_outR1: match network
Jun 25 07:28:11 draytek01 draytek01: Accept ESP proposal ENCR ESP_AES, HASH AUTH_ALGORITHM_HMAC_SHA1
Jun 25 07:28:11 draytek01 draytek01: Responding to Quick Mode from xx.xxx.xxx.xxx
Jun 25 07:28:11 draytek01 draytek01: IKE ==>, Next Payload=ISAKMP_NEXT_HASH, Exchange Type = 0x20, Message ID = 0x1
Jun 25 07:28:11 draytek01 draytek01: IKE <==, Next Payload=ISAKMP_NEXT_HASH, Exchange Type = 0x20, Message ID = 0x1
Jun 25 07:28:11 draytek01 draytek01: IPsec SA #402 will be replaced after 2850 seconds
Jun 25 07:28:11 draytek01 draytek01: #402 IPsec SA established with xx.xxx.xxx.xxx. In/Out Index: 34/0
Jun 25 07:28:23 draytek01 draytek01: [L2TP][@0.0.0.0] IKE link timeout: state wait_L2
Jun 25 07:28:23 draytek01 draytek01: [L2TP][@0.0.0.0] pppShutdown
###
Firmware Version: 3.9.2_BT
SmartVPN 5.3.1
If anyone knows of a solution to these L2TP IKE link timeout errors , It would be greatly appreciated.
Please Log in or Create an account to join the conversation.
- ndp
- Topic Author
- Offline
- New Member
Less
More
- Posts: 6
- Thank you received: 0
25 Jun 2020 10:35 #96502
by ndp
Replied by ndp on topic Re: Vigor 2762 L2TP/IPsec from SmartVPN - timeout errors
I figured it out for myself.
The ISP (GiffGaff) of my 4G router is assigning 2 different IP addressess to the router one with an "82." prefix which the outside world sees, and a "10.145." prefix that the router thinks is it's external IP.
When I disconnected my laptop from the 4G router and tethered it to my phone (Vodafone), the problem went away and I am able to connect to my Vigor 2762 via L2TP/IPsec.
I guess I'll ditch my 4G router's GiffGaff SIM Card and replace it with one from another network such as Vodafone.
The ISP (GiffGaff) of my 4G router is assigning 2 different IP addressess to the router one with an "82." prefix which the outside world sees, and a "10.145." prefix that the router thinks is it's external IP.
When I disconnected my laptop from the 4G router and tethered it to my phone (Vodafone), the problem went away and I am able to connect to my Vigor 2762 via L2TP/IPsec.
I guess I'll ditch my 4G router's GiffGaff SIM Card and replace it with one from another network such as Vodafone.
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek