ipsec tunnel works but l2tp doesn't with same certificates

From: James (James_at_discussions.microsoft.com)
Date: 12/21/04


Date: Tue, 21 Dec 2004 09:37:04 -0800

I have set up a l2tp remote access vpn on my LAN. The VPN Server is running
Windows 2003 with a static address pool and other default settings and the
client has L2TP/IPSec VPN set, firewall off and default security. I have
installed certificates onto the local computer of each machine from the same
Enterprise CA and made sure they both have Root Certificates.

When I try to connect from the client the following error appears:

Error 789: The L2TP connection attempt failed because the security layer
encountered a processing error during initial negotiations with the remote
computer

However, if I assign an IPSec policy using the same certifcates to
authenticate and connect using the same L2TP client connection it works.
What can be stopping the L2TP vpn?

Any help greatly appreciated. Thankyou



Relevant Pages

  • PIX 501 VPN connection problem
    ... I have set up a new PIX 501 (with 10 VPN licenses) at home to protect ... or standard Windows XP L2TP connection from outside. ... isakmp policy 20 authentication pre-share ... vpdn group L2TP-VPDN-GROUP ppp authentication mschap ...
    (comp.security.firewalls)
  • Re: L2TP over Wireless and NAT
    ... L2TP VPNs can use certificates or a Pre-Shared Key... ... My Networking Blog: http://www.networkblog.net ... >> I am trying to configure an L2TP/IPSec connection from my home to my office ... We have been using PPTP for VPN for some time now in the ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: VPN server
    ... PPTP is encrypted, you can use L2TP without certificates. ... You can use a pre-shared key instead of a certificate for L2TP/IPSec ... Well you have to configure the RRAS VPN service (see buiilt-in Help* or ...
    (microsoft.public.windows.server.active_directory)
  • Re: VPN server
    ... You have to choose either/both PPTP or L2TP (which uses IPSec) for the ... (Dial-in tab even though this is VPN) ...
    (microsoft.public.windows.server.active_directory)
  • Re: HELP VPN NIGHTMARE!!!
    ... MS Remote Access can handle a lot more sessions that what you use. ... Are you use l2tp? ... If you are not using l2tp, which would require a W2003 vpn server and nat-t ... > I have several stores that vpn into the main store, most store can run for days on ...
    (microsoft.public.win2000.networking)