We have an MX100 that has the client VPN functionality enabled. This is using RADIUS authentication and is configured to communicate with a DC that has this role installed and configured.
I can successfully connect to this from my own laptop and some test machines that are not on the client domain, however machines on the client domain (and a coupe of others that are not) cannot connect at all.
I am trying to connect with identical credentials on all machines and the same internet connection and some machines will connect and others will not. the clients that do not connect get an entry for Error 789 in Event Viewer. The error from the VPN connection is "The L2TP connection attempt failed because the security layer encountered a processing error during initial negotiations with the remote computer"
We have checked that the "IKE and Auth..." service and the IPSEC Processing Policy service are running.
The logs on the Meraki show the following:
Dec 12 15:04:36 | | Non-Meraki / Client VPN negotiation | msg: phase1 negotiation failed due to time up. 59c9b9d31a1ca7fc:e7241141149e770f |
Dec 12 15:03:49 | | Non-Meraki / Client VPN negotiation | msg: phase1 negotiation failed due to time up. 6a8f5861211ce0a4:0192fd20f7d239be |
Dec 12 15:03:46 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 19. |
Dec 12 15:03:46 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 20. |
Dec 12 15:03:46 | | Non-Meraki / Client VPN negotiation | msg: received broken Microsoft ID: MS NT5 ISAKMPOAKLEY |
Dec 12 15:02:59 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 19. |
Dec 12 15:02:59 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 20. |
Dec 12 15:02:58 | | Non-Meraki / Client VPN negotiation | msg: received broken Microsoft ID: MS NT5 ISAKMPOAKLEY |
Dec 12 15:01:05 | | Non-Meraki / Client VPN negotiation | msg: phase1 negotiation failed due to time up. 5c8c3fed81ed0dfa:344388c60cc91c1e |
Dec 12 15:00:54 | | Non-Meraki / Client VPN negotiation | msg: unknown Informational exchange received. |
Dec 12 15:00:54 | | Non-Meraki / Client VPN negotiation | msg: ISAKMP-SA deleted x.x.x.x[500]-x.x.x.x[500] spi:8019f7f3eac784dc:79e6de84ffa397eb |
Dec 12 15:00:54 | | Non-Meraki / Client VPN negotiation | msg: ISAKMP-SA expired x.x.x.x[500]-x.x.x.x[500] spi:8019f7f3eac784dc:79e6de84ffa397eb |
Dec 12 15:00:18 | | Non-Meraki / Client VPN negotiation | msg: phase1 negotiation failed due to time up. d3619ad0e8a97674:070ff11a8655461d |
Dec 12 15:00:15 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 19. |
Dec 12 15:00:15 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 20. |
Dec 12 15:00:15 | | Non-Meraki / Client VPN negotiation | msg: received broken Microsoft ID: MS NT5 ISAKMPOAKLEY |
Dec 12 14:59:28 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 19. |
Dec 12 14:59:28 | | Non-Meraki / Client VPN negotiation | msg: invalid DH group 20. |
Dec 12 14:59:28 | | Non-Meraki / Client VPN negotiation | msg: received broken Microsoft ID: MS NT5 ISAKMPOAKLEY |