Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
schmil
New Contributor

L2TP with ModeConfig and Split Tunnel

L2TP seemed not to work with Mode Config enable. Wanted to get Split Tunneling enabled.

 

When I enable Mode Config, no connection occurs. It seem the client is waiting for a IP?

 

Last in 'diag deb app ike -1' I see is:

ike 7:L2TP:358: responder:main mode get 2nd message...
ike 7:L2TP:358: NAT not detected
ike 7:L2TP:358: out DAA648EFB2B9128486CD6487A1C43AF90410020000000000000000E40A000084E4FAE9690F1851342A92BB732F696E161552CA14CF9CFDE3F5EFD06E458064878AA0489ED0C5B2E5B64D63AD9B51C8302087886762889E263D131133E893EDC460166972B5D1E8EEFBFF7EAD4655788755E60D31F30D43A96494D51B929E66F394621CE42B2A8F1F81DFC74F27BEE8CE072C01C0D3DD8BE846E1DCBE104051E978140000147F8FDA6AC8B17D33042BA7D62D1E057714000018E4E39879E62E7B5E183EE868F99A4094ADEF1C78000000189F7A4EC94E059F6D7D12857FDC087638624FFE20
ike 7:L2TP:358: sent IKE msg (ident_r2send): 192.168.2.2:500->192.168.2.11:500, len=228, id=daa648efb2b91284/86cdt6487a1c43af9
ike 7:L2TP:358: ISAKMP SA daa648efb2b91284/86cd6487a1c43af9 key 24:F604FFFB39AEB41C0204E187C42C3DEFBAF7B82CFB7DE0F7
ike 7: comes 192.168.2.11:500->192.168.2.2:500,ifindex=13....
ike 7: IKEv1 exchange=Identity Protection id=daa648efb2b91284/86cd6487a1c43af9 len=68
ike 7: in DAA648EFB2B9128486CD6487A1C43AF940510020100000000000000442DA0234FD9232B9A8C69C2BF7A4F1D38382A2442271E2770AE08BFC4951B42E60ADB3FDCB32D2B63
ike 7:L2TP:358: responder: main mode get 3rd message...
ike 7:L2TP:358: dec DAA648EFB2B9128486CD6487A1C43AF90510020100000000000000440800000C010000008249490B000000189C2A26604B35D29DB614B7FF68948FBD2C8DA4AF00000000
ike 7:L2TP:358: peer identifier IPV4_ADDR 192.168.2.11
ike 7:L2TP:358: PSK authentication succeeded
ike 7:L2TP:358: authentication OK
ike 7:L2TP:358: enc DAA648EFB2B9128486CD6487A1C43AF90510020100000000000000400800000C01000000824948020000001861F42F1993766E75D8C0B8A174FBF7D4EB5C38A2
ike 7:L2TP:358: out DAA648EFB2B9128486CD6487A1C43AF9051002010000000000000044ED3B9D194573C5AE3D03B3D020696F1359D1D574B8EE4DBD6E267037669408A8878EF64C8E2054BA
ike 7:L2TP:358: sent IKE msg (ident_r3send): 192.168.2.2:500->192.168.2.11:500, len=68, id=daa648efb2b91284/86cd6487a1c43af9
ike 7:L2TP: adding new dynamic tunnel for 192.168.2.11:500
ike 7:L2TP_0: added new dynamic tunnel for 192.168.2.11:500
ike 7:L2TP_0:358: established IKE SA daa648efb2b91284/86cd6487a1c43af9
ike 7:L2TP_0: DPD disabled, not negotiated
ike 7:L2TP_0:358: no pending Quick-Mode negotiations

 

 

 

 

 

 

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors