Hi Forum,
I have a customer that has a MX Device behind a NAT Router and the client wants to have the Client VPN feature enabled so we are busy testing this for him using the Meraki Cloud Authentication. We are not able to configure the NAT Router in Bridge mode but we have configured it to forward UDP500 and UDP4500 ports to the MX device.
Before we configured the router to forward UDP 500 and UDP 4500 to the MX Device, we were not able to connect and we were receiving an L2TP Error message on the Windows 10 device. We were also not seeing any events in the Event Log on the MX Device. After forwarding these ports to the MX Device, we are now seeing the events in the Event Log and it seems as if the MX device is completing the connection but we still get a failed connection on the Windows 10 device ("The connection was terminated by the remote compute before it could be completed")
Below is an output of the events in the MX Event Log:
Jun 29 15:57:26 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|5> deleting IKE_SA l2tp-over-ipsec-1[5] between 192.168.8.101[192.168.8.101]...169.159.156.42[10.0.2.15] |
Jun 29 15:57:26 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|5> closing CHILD_SA net-1{17} with SPIs c3e94349(inbound) (825 bytes) a8824164(outbound) (721 bytes) and TS 192.168.8.101/32[udp/l2f] === 169.159.156.42/32[udp/l2f] |
Jun 29 15:57:25 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|5> CHILD_SA net-1{17} established with SPIs c3e94349(inbound) a8824164(outbound) and TS 192.168.8.101/32[udp/l2f] === 169.159.156.42/32[udp/l2f] |
Jun 29 15:57:24 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|5> IKE_SA l2tp-over-ipsec-1[5] established between 192.168.8.101[192.168.8.101]...169.159.156.42[10.0.2.15] |
Jun 29 15:53:32 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|3> deleting IKE_SA l2tp-over-ipsec-1[3] between 192.168.8.101[192.168.8.101]...169.159.156.42[10.0.2.15] |
Jun 29 15:53:32 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|3> closing CHILD_SA net-1{16} with SPIs c8d42dee(inbound) (825 bytes) a67b2806(outbound) (721 bytes) and TS 192.168.8.101/32[udp/l2f] === 169.159.156.42/32[udp/l2f] |
Jun 29 15:53:31 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|3> CHILD_SA net-1{16} established with SPIs c8d42dee(inbound) a67b2806(outbound) and TS 192.168.8.101/32[udp/l2f] === 169.159.156.42/32[udp/l2f] |
Jun 29 15:53:30 | | Non-Meraki / Client VPN negotiation | msg: <l2tp-over-ipsec-1|3> IKE_SA l2tp-over-ipsec-1[3] established between 192.168.8.101[192.168.8.101]...169.159.156.42[10.0.2.15] |