ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    EdgeRouter L2TP VPN can't pass IKE phase 1

    IT Discussion
    l2tp edgeos 1.10.6 edgerouter lite vpn
    4
    23
    4.5k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • RomoR
      Romo
      last edited by Romo

      A DNAT rule was the culprit of everything, it was redirecting the traffic and not letting it reach WAN_LOCAL.

      FINALLY SOLVED!!!!!!!!!!!!!!!!!!!!!!!!!


      As reminder for anyone that could encounter a similar issue:
      DNAT rules are evaluated before firewall rules.

      scottalanmillerS JaredBuschJ 2 Replies Last reply Reply Quote 1
      • scottalanmillerS
        scottalanmiller @Romo
        last edited by

        @romo said in EdgeRouter L2TP VPN can't pass IKE phase 1:

        A DNAT rule was the culprit of everything, it was redirecting the traffic and not letting it reach WAN_LOCAL.

        FINALLY SOLVED!!!!!!!!!!!!!!!!!!!!!!!!!


        As reminder for anyone that could encounter a similar issue:
        DNAT rules are evaluated before firewall rules.

        Also as a remember, don't wait a month before reporting an issue, we weren't looking at rules, as they had not changed for a month!

        1 Reply Last reply Reply Quote 2
        • JaredBuschJ
          JaredBusch @Romo
          last edited by JaredBusch

          @romo said in EdgeRouter L2TP VPN can't pass IKE phase 1:

          A DNAT rule was the culprit of everything, it was redirecting the traffic and not letting it reach WAN_LOCAL.

          FINALLY SOLVED!!!!!!!!!!!!!!!!!!!!!!!!!


          As reminder for anyone that could encounter a similar issue:
          DNAT rules are evaluated before firewall rules.

          Yes, this is a known function of VyOS/EdgeOS. But nothing was ever posted baout DNAT rules in use, so I assumed there were none. There are not by default.

          1 Reply Last reply Reply Quote 0
          • 1
          • 2
          • 2 / 2
          • First post
            Last post