Client VPN Assistance

ktv-meraki
Here to help

Client VPN Assistance

Hello!

We have Client VPN setup successfully on our primary MX at one site using the L2TP over IPsec configuration. It points to a Windows Server using NPS.  I am looking at duplicating that same scenario at our secondary site.  I essentially copied our current configuration with the exception of changing the host name and deployed it to my windows machine. When i attempt to connect, Windows prompts for credentials, but eventually gives me an error, "The remote connection was denied because the username and password combination you provided is not recognized or the selected authentication protocol is not permitted on the remote access server."

 I do see these errors in Meraki: 

 

Jun 15 11:23:44

 

Non-Meraki / Client VPN

Non-Meraki / Client VPN negotiation

msg: <l2tp-over-ipsec-1|998> deleting IKE_SA l2tp-over-ipsec-1[998] between 175.165.112.219[165.166.112.219]...61.85.127.191[172.30.20.12]

Jun 15 11:23:44

 

 

Non-Meraki / Client VPN

Non-Meraki / Client VPN negotiation

msg: <l2tp-over-ipsec-1|998> closing CHILD_SA net-1{1482} with SPIs ca095fa1(inbound) (947 bytes) 5a2f103c(outbound) (666 bytes) and TS 175.165.112.219/32[udp/l2f] === 61.85.127.191/32[udp/l2f]

Jun 15 11:23:10

 

 

Non-Meraki / Client VPN

Non-Meraki / Client VPN negotiation

msg: <l2tp-over-ipsec-1|998> CHILD_SA net-1{1482} established with SPIs ca095fa1(inbound) 5a2f103c(outbound) and TS 175.165.112.219/32[udp/l2f] === 61.85.127.191/32[udp/l2f]

Jun 15 11:23:10

 

 

Non-Meraki / Client VPN

Non-Meraki / Client VPN negotiation

msg: <l2tp-over-ipsec-1|998> IKE_SA l2tp-over-ipsec-1[998] established between 175.165.112.219[175.165.112.219]...61.85.127.191[172.30.20.12]

 

Things I have done or not done.

I have looked in the Radius log and do not see the it receiving the authentication request.

I have confirmed that the VPN adapter in Windows is set like my primary to Allow the 3 protocols listed on the Security tab, including PAP. 

I checked the registry setting on my computer for AssumeUDPEncapsulationContextOnSendRule but again, if it works for the primary, i would think i would not need to verify this.

I have NOT configured anything new on my NPS server, do I need to add this new MX as a Radius client? One aspect of the primary config that confuses me is that on the Windows NPS server, under Radius Clients, the Meraki setup shows the IP of the Radius server and not the IP of the MX.  This document outlines the need to add the IP of the MX:

https://documentation.meraki.com/MX/Client_VPN/Configuring_RADIUS_Authentication_with_Client_VPN

 

I know I must be missing something simple.  I appreciate any assistance provided.  Thank you.

 

3 Replies 3
alemabrahao
Kind of a big deal
Kind of a big deal

Is your secondary site's MX able to communicate with your Raius server? Did you validate this communication?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
ktv-meraki
Here to help

I should have included that in my post. Yes I did validate communication.  Thanks for asking!

alemabrahao
Kind of a big deal
Kind of a big deal

Ok, and yes, you need to add the MX as a Radius client. 

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels