L2TP over IPsec VPN Server

L2TP over IPsec VPN Server

Quik Tech Solutions L.L.C

7 лет назад

88,490 Просмотров

Ссылки и html тэги не поддерживаются


Комментарии:

@Sashajuma
@Sashajuma - 19.10.2023 08:05

Thanks Tony !!!

Ответить
@tamaskapocsi2266
@tamaskapocsi2266 - 06.08.2023 14:35

Hello, thanks for your work!
The tutorials are very good, but I would appreciate it if you could update it to the current software version. I am currently on the latest v2.0.9-hotfix.7 and due to errors, I cannot perform the settings either with GUI or CLI commands.

Ответить
@MajoBeats
@MajoBeats - 14.07.2023 01:00

I used exact config on my Edgerouter X and still i cant connect to it. I used NoIp service for my dynamic ip

Ответить
@JosiahGarber
@JosiahGarber - 10.07.2023 16:13

If you are trying to connect to an L2TP VPN with Android, note that it is no longer working in newer versions of Android. Just wanted to save someone some time.

Ответить
@akfit5934
@akfit5934 - 19.05.2023 00:34

Tony, you mentioned in another comment that an error can occur if you have multiple VPN's? I have 3 site-to-site VPN's that continue to work, but the L2TP connection for clients, only works temporarily (after hours during initial setup) then in the morning, the client VPN will not establish a connection. Any pointers?

Ответить
@akfit5934
@akfit5934 - 19.05.2023 00:06

So, the VPN settings worked for exactly one day. Now, I receive an error message. All settings are still in place, including firewall... Any ideas? "The network connection between your computer and the VPN server could not be established because the remote server is not responding. This could be because one of the network devices (e.g. firewalls, NAT. routers, etc) between your computer and the remote server is not configured to allow VPN connections. Please contact your Administrator or your service provider to determine which device may be causing the problem."

Ответить
@NineStarAK
@NineStarAK - 17.05.2023 06:21

Thank you sooooo much!!! I've been struggling to find a configuration that really works... Your directions were clear and totally effective. Awesome!

Ответить
@NathanTEG
@NathanTEG - 28.03.2023 20:10

Still brilliant in 2023. My issue was external connection. Internal was fine. After setting the firewall rules from the ubiquity guide i had some pre existing port forwards on port 500 and 4500. Make sure to check your exisitng forwarding rules.

Ответить
@pieterbatenburg8200
@pieterbatenburg8200 - 20.02.2023 23:57

Absolutely great video, thanks! I can now connect to my local devices, but would also like to be able to use the internet over the VPN connection. How can I get that working or did I make a mistake somewhere?

Ответить
@jeffsmallet1864
@jeffsmallet1864 - 15.01.2023 13:10

Hi Tony. What if I give you access by anydesk and you Will set vpn for me.

Ответить
@czamana
@czamana - 23.11.2022 20:04

WOW!

5 years later and this is still useful and correct!

Thank you very much Mr. Tony!

And if you allows me, here is the firewall rules to complement your script:

# Firewall rules

set firewall name WAN_LOCAL rule 30 action accept
set firewall name WAN_LOCAL rule 30 description IKE
set firewall name WAN_LOCAL rule 30 destination port 500
set firewall name WAN_LOCAL rule 30 log disable
set firewall name WAN_LOCAL rule 30 protocol udp

set firewall name WAN_LOCAL rule 40 action accept
set firewall name WAN_LOCAL rule 40 description ESP
set firewall name WAN_LOCAL rule 40 log disable
set firewall name WAN_LOCAL rule 40 protocol esp

set firewall name WAN_LOCAL rule 50 action accept
set firewall name WAN_LOCAL rule 50 description NAT-T
set firewall name WAN_LOCAL rule 50 destination port 4500
set firewall name WAN_LOCAL rule 50 log disable
set firewall name WAN_LOCAL rule 50 protocol udp

set firewall name WAN_LOCAL rule 60 action accept
set firewall name WAN_LOCAL rule 60 description L2TP
set firewall name WAN_LOCAL rule 60 destination port 1701
set firewall name WAN_LOCAL rule 60 ipse match-ipsec
set firewall name WAN_LOCAL rule 60 log disable
set firewall name WAN_LOCAL rule 60 protocol udp

And if you want to debug the connections, execute in CLI/SSH:

swanctl --log


Thank you!!!

Ответить
@wisplosred9606
@wisplosred9606 - 26.10.2022 07:45

Hi, the video is grate. but, I haven´t Ip public, and have 2 nat over on my ErL... I configure using Noip, thinking what the server will works, but not. some idea?
The VPN works in my iPhone locally, but not in 4G AT&T

Ответить
@ianperera7580
@ianperera7580 - 14.07.2022 17:20

This works great, but how can I allow multiple connections from one public IP

Ответить
@richardrawlings181
@richardrawlings181 - 21.06.2022 18:13

Followed this step by step and cant connect from a windows machine

Ответить
@DRSGHAZAL
@DRSGHAZAL - 03.05.2022 10:25

Hi and thanks for the video. Now after android 12 removed L2TP, is thetr any way I can connect my android 12 to my edge router?
Thanks

Ответить
@vincenzorusso4801
@vincenzorusso4801 - 29.03.2022 13:37

wonderful video.
can you explain how to connect lan in vpn with a edgerouter lite and a fritzbox 7590? (formely a vpn router to router)
thank you excuse my bad english

Ответить
@Steveshiflet
@Steveshiflet - 25.01.2022 06:41

First, thank you for making this excellent tutorial. I have scoured the internet and your video is by far the best I have found for this topic. I am unable to make this work for me, and I know it is because of something I am doing wrong - in spite of deleting and re-adding a few times. Have you considered making an updated version of this video? As the version of the Edgerouter UI has changed quite a bit, it would be great to see a new tutorial. Plus, L2TP is considered unsecure and no one else has made a (good) recent video of how to setup a more secure VPN in this space.

Ответить
@rent2ownnz
@rent2ownnz - 07.01.2022 20:13

did not work for me.... I did everything line by line and all the firewall rules.... be nice if you could do a trouble shooting video in case this does not work. I have successfully set up a PPTN VPN using another video.

Ответить
@user-zm4oy6mf5z
@user-zm4oy6mf5z - 02.01.2022 04:06

Ran into problems with Android. The Edgerouter didn't like the CHAP response and there was nothing to tweak in Android.

Ответить
@arlenreyes4283
@arlenreyes4283 - 30.12.2021 19:32

How would I setup this with double nat bc can't eliminate ISP router?

Ответить
@wasifbhatti9480
@wasifbhatti9480 - 18.09.2021 14:56

Nice and crisp, easy to follow instructions, right to the point, thank you for creating the video. Stay blessed.

Ответить
@videoer0
@videoer0 - 03.09.2021 00:59

Thank you for this video. It was very easy to follow and made it easy to set up VPN on my own router.

Ответить
@Ole_Friis_Heesgaard
@Ole_Friis_Heesgaard - 17.08.2021 11:45

Thanks for a great good video.
Does remote users get internet through their own router or through the l2tp servers gateway?

Ответить
@martinmenard9451
@martinmenard9451 - 12.08.2021 20:28

Hi Tony. I've set this up, and it connects properly and uses my home connection to access the internet. However, I can't seem to connect to any local resources (printers, servers, etc...). Any ideas?

Ответить
@juanjosecuen6709
@juanjosecuen6709 - 29.07.2021 07:20

Good afternoon sir. How do I create the PPPoE interface? I tried adding it from the Dashboard (Add Interface/PPPoE) and even though it adds the interface to the Dashboard, , it does not shows as an option of the Interface the drop down . thanks!

Ответить
@hellohello1321
@hellohello1321 - 07.06.2021 17:51

Just want to say thank you for the video. I have used this to successfully configure my EdgeRouter and connected via my Android device!

Ответить
@Goompsify
@Goompsify - 17.05.2021 18:40

Hi Tony. I have dual wan on my Edge pro router all with static IPs. I have followed all procedure but seems not to wor

Ответить
@markarca6360
@markarca6360 - 11.04.2021 14:09

For Android/Samsung devices: Tap the Settings app, then choose More Connection Settings, and then select VPN, then select More. Depending on your requirements select either VPN, choose Add VPN or Always-on VPN.

Ответить
@monteduncan
@monteduncan - 20.03.2021 19:25

Super helpful! I have used this video twice now (had to reconfigure my edge-router) and both times process went smoothly because your video was so easy to follow! Thanks for a job well done!!

Ответить
@user-ot8dw3qi2u
@user-ot8dw3qi2u - 25.02.2021 11:49

It works, thank you!!!

Ответить
@bartek2028
@bartek2028 - 20.01.2021 12:45

Thank you sir, worked for the first time. Now finally after long time and tries i'm able to wake my pc from my smartphone/remote access. Works like a charm. Greetings from Germany

Ответить
@keithstanley7313
@keithstanley7313 - 20.01.2021 03:29

Great video and still appears timely. I am surprised you did not add "set vpn ipsec auto-firewall-nat-exclude enable". I had to add this line to get to my vlans. Am I missing something?

Ответить
@rhether
@rhether - 01.01.2021 21:36

Just set this up today with my EdgeRouterX SFP, so much better than reading thru tutorials on the web. I enjoy all your vids and Happy New Year.

Ответить
@y.l.8361
@y.l.8361 - 26.12.2020 20:22

Thanks a lot for the video!!! If I do the L2TP via the config. tree, are there any steps needed besides what you showed int he video? Thanks

Ответить
@kosmicken
@kosmicken - 18.11.2020 17:55

I have an HP LaserJet printer on my network, and I was hoping to be able to print from the VPN, but sadly, the printer does not show up when a device is connected to the VPN. Is there a way to get this to work?

Ответить
@kosmicken
@kosmicken - 15.11.2020 23:44

Thanks, Tony! I was able to follow along and set this up in no time. Works like a charm. I can access my devices on my home network and use my Pi-Hole for ad blocking when away from home. Those were my two goals. Does this also encrypt traffic like commercial VPNs do for the purpose of security when connected to a public hot spot?

Ответить
@Motorman2112
@Motorman2112 - 12.11.2020 20:56

Thanks for this. I would like to allow remote users to access a LAN at another site, can this be done over the same IP address the site uses for internet access, or does it require multiple IPs?

Ответить
@jslegers1973
@jslegers1973 - 13.10.2020 16:56

Great video thank you. Short Question how can you temporarily disable the VPN?

Ответить
@xkompotikx
@xkompotikx - 02.10.2020 12:07

Thank you Tony for the great instructions. Clear and understandable. I wish you many more such tutorials. Best regards from Slovakia

Ответить
@70Stang
@70Stang - 01.09.2020 04:07

Tony, thanks BTW! great video

Ответить
@70Stang
@70Stang - 01.09.2020 04:06

Using a Windows 10 machine was an issue for me. I searched and found what was preventing my connection. After you create the Windows VPN, make sure to edit the VPN connection in Network Connections. Right Click on the VPN connection you just created, click properties, click security, enable "Allow these protocols" and select CHAP & MS-CHAP v2).

Ответить
@kosmicken
@kosmicken - 29.08.2020 20:14

Thanks for laying it all out and making it easy to follow. I'm going to set this up soon. Couple quick questions. Do the DHCP servers have to be public or can the be internal? One of the reasons I want to set up a VPN is so I can use Pi-Hole from outside my network to block ads, so I would want to use the Pi-Hole's internal IP address as the primary DHCP, with a public as a backup. Second, does the client address pool have to be part of the existing internal DHCP range, separate from that range, or does it not matter? I did not realize this pool needed to be specified, as I assumed the client would receive an address from the existing DHCP pool. Hope that makes sense.

Ответить
@sphillips8362
@sphillips8362 - 06.08.2020 00:19

Can this be done via ssh to the router?

Ответить
@viviroig5336
@viviroig5336 - 03.08.2020 00:13

how do i delete it please help!

Ответить
@scotthepler5694
@scotthepler5694 - 02.08.2020 18:25

Hello Tony, This is a great video. I really like how you describe how and why. Can you tell me how to create the pre-shared-secret?

Ответить
@fengjingbao
@fengjingbao - 29.07.2020 00:20

I was able to set up my VPN only by adding a firewall rule to allow PING. Otherwise I was not able to access the VPN. Is this rule absolutely necessary?

Ответить