L2TP VPN connection fails in a test environment
data:image/s3,"s3://crabby-images/65ce4/65ce48eac8f99fe676e457cf465639a6a9c54114" alt=""
I could not get a L2TP client to lan configuration to work on my ER605. I took it out of service and put it in a test environment to troubleshoot it. I have the following:
Local Area network IP range: 192.168.1.0/24
Windows 11 client IP address: 192.168.1.103
ER605 WAN Port Address: 192.168.1.108
ER605 LAN Port Address: 10.35.0.1
ER605 LAN IP range 10.35.0.0/24
Windows 11 client on the ER605 IP Address 10.35.0.101
Both Windows 11 clients can reach the internet.
I want to setup a L2TP/IPSEC tunnel such that the Windows client at 192.168.1.103 can RDP to the Windows client at 10.35.0.101. I have configured the ER605 as follows:
VPN IP Pool:
L2TP VPN:
VPN User:
On the Windows 11 connecting client I have the L2PT client configured as follows:
I have tried every possible combination of authentication protocols in the following screen with no success:
Every time I try to connect I get an immediate error: "The L2TP connection attempt failed because the security policy for the connection was not found". In the Event Viewer I see the following error: "CoId={CBEE639E-5C4F-0003-EA3D-24CC4F5CDB01}: The user HOME\jheimann dialed a connection named Test which has failed. The error code returned on failure is 791."
I cannot get this to work. What am I doing wrong? Any help would be greatly appreciated.
Thanks,
Testing John
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Hi @TestingJohn
Thanks for posting in our business forum.
I think you could use the configuration guide again. The error now is that the LAN and WAN conflicts.
- Copy Link
- Report Inappropriate Content
The WAN address is 192.168.1.108 and the LAN address is 10.35.0.1. There is no conflict between the WAN and LAN address on the router. My connecting Windows client is on the same subnet as the routers WAN port so there is no routing or NATing going on outside of the router itself. The client Inam trying to connect to (through the VPN) is 10.35.0.101.
i believe I configured everything according to the guide, but I am sure I missed something since it doesn't work.
any help or guidance would be appreciated.
thanks,
Testing John
- Copy Link
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/b6fbd/b6fbde2befdfa7062fa9672519a9cbdb9cddc9fe" alt=""
Hi @TestingJohn
Thanks for posting in our business forum.
TestingJohn wrote
The WAN address is 192.168.1.108 and the LAN address is 10.35.0.1. There is no conflict between the WAN and LAN address on the router. My connecting Windows client is on the same subnet as the routers WAN port so there is no routing or NATing going on outside of the router itself. The client Inam trying to connect to (through the VPN) is 10.35.0.101.
i believe I configured everything according to the guide, but I am sure I missed something since it doesn't work.
any help or guidance would be appreciated.
thanks,
Testing John
That's WAN subnet/CIDR.
But why is the client on 192.168.1.0/24?
- Copy Link
- Report Inappropriate Content
Thank you for pointing out my error. I changed the local IP address from 91.68.1.103 to a non conflicting address 172.16.1.100.
I tried to connect again and it immediately failed with the same error message: "The L2TP connection attempt failed because security policy for the connection was not found". I also have the same error in the event log: "CoId={CBEE639E-5C4F-0002-AFBB-91CC4F5CDB01}: The user HOME\jheimann dialed a connection named Test which has failed. The error code returned on failure is 791."
Not sure what I am doing wrong? Any help would be appreciated.
Thanks,
Testing John
- Copy Link
- Report Inappropriate Content
Interestingly enough, if I make the local IP address in the same network as the VPN IP Pool in preferences (172.16.0.19 in my case), the error message is different. In this case I get "The L2P connection attempt failed because the security layer encountered a processing error due to initial negotiations with the remote computer.". In the event log the error message is also different: "CoId={CBEE639E-5C4F-0003-162C-76CC4F5CDB01}: The user HOME\jheimann dialed a connection named Test which has failed. The error code returned on failure is 789."
I know I have something miss configured, but for the life of me, I can't figure out what. Any help would be greatly appreciated.
Thanks,
Testing John
- Copy Link
- Report Inappropriate Content
Hi @TestingJohn
Thanks for posting in our business forum.
TestingJohn wrote
Interestingly enough, if I make the local IP address in the same network as the VPN IP Pool in preferences (172.16.0.19 in my case), the error message is different. In this case I get "The L2P connection attempt failed because the security layer encountered a processing error due to initial negotiations with the remote computer.". In the event log the error message is also different: "CoId={CBEE639E-5C4F-0003-162C-76CC4F5CDB01}: The user HOME\jheimann dialed a connection named Test which has failed. The error code returned on failure is 789."
I know I have something miss configured, but for the life of me, I can't figure out what. Any help would be greatly appreciated.
Thanks,
Testing John
So, I require a diagram of your network with IP specified on it. And you should follow exactly what the FAQ tells you on the L2TP configuration.
And describe steps on how you make a connection on what port and what IP you get and try to connect.
If you cannot do this, or describe it clearly, contact phone support or any instant support. This reply back and forth is not making concrete progress here. These errors do not make sense to me as I am not an MS software engineer. In a local environment, I actually never encounter issues with the connection. Only when you are making the wrong connections.
Based on what I learned so far, I believe you have misconfigured your VPN, and messed up with the physical connection when you do a local test in your current environment.
- Copy Link
- Report Inappropriate Content
Below is my network diagram. As you can see this is a controlled test environment. The goal is to setup the ER605 to allow a L2TP connection between PC1 192.168.1.103 and 10.35.0.0/24 network, so that PC1 can RDP into PC2. Both PCs are Windows 11 with all the latest MS updates installed. I decided to put this in a controlled test environment after failing to get it to work at a customer site in a real environment.
No matter how I try and configure the ER605 L2TP Client to LAN, I cannot get past the errors on PC1 when trying to connect to the VPN. On the ER605 I have configured the VPN IP Pool as follows:
On the ER605, I configured the L2TP Server as follows:
On the ER605 I configure the VPN User as follows:
On PC1 I configure the L2TP client connection as follows:
With More Properties set as follows on PC1:
When I attempt to connect PC1 to the VPN I get the following error: "The L2TP connection attempt failed because the security policy for the connection was not found". In the Event Viewer I see the following error: "CoId={CBEE639E-5C4F-0003-EA3D-24CC4F5CDB01}: The user HOME\jheimann dialed a connection named Test which has failed. The error code returned on failure is 791."
I am clearly doing something wrong, but for the life of me can't figure out what?
Thanks,
Testing John
- Copy Link
- Report Inappropriate Content
Hi @TestingJohn
Thanks for posting in our business forum.
TestingJohn wrote
Below is my network diagram. As you can see this is a controlled test environment. The goal is to setup the ER605 to allow a L2TP connection between PC1 192.168.1.103 and 10.35.0.0/24 network, so that PC1 can RDP into PC2. Both PCs are Windows 11 with all the latest MS updates installed. I decided to put this in a controlled test environment after failing to get it to work at a customer site in a real environment.
No matter how I try and configure the ER605 L2TP Client to LAN, I cannot get past the errors on PC1 when trying to connect to the VPN. On the ER605 I have configured the VPN IP Pool as follows:
On the ER605, I configured the L2TP Server as follows:
On the ER605 I configure the VPN User as follows:
On PC1 I configure the L2TP client connection as follows:
With More Properties set as follows on PC1:
When I attempt to connect PC1 to the VPN I get the following error: "The L2TP connection attempt failed because the security policy for the connection was not found". In the Event Viewer I see the following error: "CoId={CBEE639E-5C4F-0003-EA3D-24CC4F5CDB01}: The user HOME\jheimann dialed a connection named Test which has failed. The error code returned on failure is 791."
I am clearly doing something wrong, but for the life of me can't figure out what?
Thanks,
Testing John
Have you tried a different computer? MAC or iOS/Android or anything else?
I see the client password is 8-digit, and you input 10 on the Windows.
And you could use this guide for configuration: https://www.tp-link.com/en/support/faq/1629/
- Copy Link
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/65ce4/65ce48eac8f99fe676e457cf465639a6a9c54114" alt=""
Information
Helpful: 0
Views: 449
Replies: 9
Voters 0
No one has voted for it yet.