Issue L2TP over IPSEC with Radius and NPS
Hi all!
Currently I am configuring a L2TP over IPSEC through Radius with a NPS server.
I've configured the L2TP on the Fortigate with the wizard, this is quite simple.
For testing I created 2 L2TP configuration because of the different networks available to connect with as a user.
This is a L2TP configuration for a native Windows client.
Tunnel:
-Remote Access - Windows Native
-Incoming interface - WAN
-Preshared key: ****
-User Group - the VPN Radius Group that should match
-Local interface - the interface that matches the destination group
-Local address - the address object that matches the destination group
-Client address range - a fictive range I made up 10.10.44.100-10.10.44.200
When connecting from a Windows client, it stops with error code: 691 (remote connection denied username..)
But checking the NPS logs, it shows MS-CHAPv2 was successful.
The logs matches the exact group that belongs to the user and I see traffic on the policies. So this should be good to go.
But showing the debug from the Fortigate, it shows " MSCHAP-v2 peer authentication failed for remote host".
So the NPS-Server says "successful" but the Fortigate says failed.
Does anyone recognise this issue?
Best regards,
Tim
