Hello!
I have an odd problem with L2TP server over IPSEC on my FG-100F box running 7.4.6 software.
My configuration:
config vpn ipsec phase1-interface
edit "L2TP-VOLZ"
set type dynamic
set interface "VLAN96-TESTLAB"
set ike-version 2
set peertype any
set net-device enable
set proposal aes256-sha512
set dpd on-idle
set psksecret ENC <removed>
set dpd-retryinterval 60
next
end
config vpn ipsec phase2-interface
edit "L2TP-VOLZ"
set phase1name "L2TP-VOLZ"
set proposal aes256gcm
set encapsulation transport-mode
set l2tp enable
next
end
config vpn l2tp
set status enable
set eip 10.100.251.254
set sip 10.100.251.1
set enforce-ipsec enable
set usrgrp "IPSEC VPN"
end
config system interface
edit "l2t.TESTLAB"
set vdom "TESTLAB"
set allowaccess ping
set type tunnel
set snmp-index 99
next
end
config system interface
edit "L2TP-VOLZ"
set vdom "TESTLAB"
set ip 0.0.0.0 255.255.255.255
set allowaccess ping
set type tunnel
set snmp-index 129
set interface "VLAN96-TESTLAB"
next
end
config router static
edit 4
set dst 10.100.251.0 255.255.255.0
set device "l2t.TESTLAB"
next
endRemote router connects successfully, it gets IP address 10.100.251.2 on its side.
But there is some issues.
1. It looks like Fortigate allocates 10.100.251.1 on its side, but it seems that it is not bound to any interface:
gw-fond-2 (TESTLAB) # diag ip address list | grep 10.100.251.1-- empty output.
2. As a result, customer is not able to ping 10.100.251.1, and Fortigate is not able to ping customer as well:
gw-fond-2 (TESTLAB) # execute ping-options source 10.100.251.1
gw-fond-2 (TESTLAB) # execute ping 10.100.251.2
PING 10.100.251.2 (10.100.251.2): 56 data bytes
--- 10.100.251.2 ping statistics ---
5 packets transmitted, 0 packets received, 100% packet loss3. L2TP VPN diagnostic commands both return empty outputs:
gw-fond-2 (TESTLAB) # diag vpn l2tp status-- empty
gw-fond-2 (TESTLAB) # diag vpn l2tp tunnel-- empty.
4. OSPF is not able to run over L2TP tunnels because it does not see any interfaces.
What am I doing wrong? Thanks!
Solved! Go to Solution.
@funkylicious wrote:hi,
try configuring 10.100.251.1/32 address on l2t.TESTLAB interface and 10.100.251.2/24 as the remote.
Thank you. It helped.
So now I should add l2t.TESTLAB interface to OSPF as point-to-multipoint in order to get it working? It somewhat different that I've seen in all documentation which I was able to find...
hi,
try configuring 10.100.251.1/32 address on l2t.TESTLAB interface and 10.100.251.2/24 as the remote.
@funkylicious wrote:hi,
try configuring 10.100.251.1/32 address on l2t.TESTLAB interface and 10.100.251.2/24 as the remote.
Thank you. It helped.
So now I should add l2t.TESTLAB interface to OSPF as point-to-multipoint in order to get it working? It somewhat different that I've seen in all documentation which I was able to find...
i think so, i dont really work so much with OSPF but it would seem resonable.
i found out the hard way while doing a migration of config for a client which had L2TP ( i dont really like to configure ) where traffic wasnt working and found this which helped me solve my issue - different from yours,
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.