<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Topic &#x27;L2TPoIPSEC problems&#x27; in forum &#x27;ZyXEL&#x27; - dslreports.com</title>
<link>http://www.dslreports.com/forum/L2TPoIPSEC-problems-27973931</link>
<description></description>
<language>en</language>
<pubDate>Fri, 24 May 2013 05:25:01 EDT</pubDate>
<lastBuildDate>Fri, 24 May 2013 05:25:01 EDT</lastBuildDate>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28131621</link>
<description><![CDATA[superataru posted : <div class="bquote"><said>said by <a href="/profile/431519" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=431519');">Anav</a>:</said><p>Thanks for the feedback superataru. If I have any questions I will give you an IM.<br> </p></div>LOL]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28131621</guid>
<pubDate>Sat, 23 Mar 2013 13:59:33 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28130941</link>
<description><![CDATA[Anav posted : Thanks for the feedback superataru. If I have any questions I will give you an IM.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28130941</guid>
<pubDate>Sat, 23 Mar 2013 09:19:08 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28130682</link>
<description><![CDATA[superataru posted : Hi all.<br>Sorry for delay. I tested again, and successfully L2TP connections from Android ad iPAD2, working only from ISP mobile connections (Vodafone), and found them very fast. (The same performances, it seems, as with DSL conncection).<br>I also routed traffic from L2TP to all IPSEC end points of H&S. Used RDP services and web pages of surveillance cameras of customer (sorry Anav, no resource browsing), with good results. Lt2p clients also use same remote-pool-addresses of SSL connections, easily, with no overlapping. I had to write down all policy routes, also to l2tp end point LAN1 (sure it was not necessary).<br>It's all ok, now. IPSEC, SSL and L2TP. Thanks all, as with suggestions and tests i improved my knowledge.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28130682</guid>
<pubDate>Sat, 23 Mar 2013 04:01:10 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28085501</link>
<description><![CDATA[Anav posted : I had to reset my router but once I have my android back up with L2TP I will help out.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28085501</guid>
<pubDate>Sat, 09 Mar 2013 10:36:12 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28085415</link>
<description><![CDATA[vikino posted : Hi all,<br>im still having issue with L2TP over IPSec with android,<br>log says that Phase 1 is completed and disconnected, but Phase 2 says Local policy mismatch, i followed Branos guides step by step, in VPN connection i have as local policy interface WAN IP, so the public IP...In my case it is internally from ISP the 192.168.140.21 but for this IP is done full NAT of an public IP...<br>Any idea?<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28085415?c=2080519&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="98875 bytes" WIDTH=600 HEIGHT=122 SRC="/r0/download/2080519.thumb600~d5209bdc92edbfdf871e84d11bbc29e0/log_err.JPG/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28085415</guid>
<pubDate>Sat, 09 Mar 2013 09:54:46 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28057059</link>
<description><![CDATA[Anav posted : Didnt seem to make a diff but was not much of a controlled attempt. I did try wifi at timmies and I could get a tv show to start but it stuttered a lot or froze,  mss set to 600.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28057059</guid>
<pubDate>Thu, 28 Feb 2013 22:16:10 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28056944</link>
<description><![CDATA[Brano posted : <div class="bquote"><said>said by <a href="/profile/431519" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=431519');">Anav</a>:</said><p>Brano I am running avast and something called Advanced Mobile Care.  Obviously lowing MSS to 600 helped somewhat but still less than adequate. <br> </p></div>I'd definitely try disabling/removing any AV tool for testing.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28056944</guid>
<pubDate>Thu, 28 Feb 2013 21:38:43 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054934</link>
<description><![CDATA[Kirby Smith posted : Brano:<br><br>I can't say that that built-in flow diagnostic wouldn't reveal what is going on between IP address pools, but from the categories shown I hadn't previously considered it.  Since I can't simulate Anav's setup, I'll have to leave it to him to investigate.<br><br>kirby]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054934</guid>
<pubDate>Thu, 28 Feb 2013 11:13:32 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054307</link>
<description><![CDATA[Anav posted : Brano I am running avast and something called Advanced Mobile Care.  Obviously lowing MSS to 600 helped somewhat but still less than adequate. Do you think the above two apps are the problem??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054307</guid>
<pubDate>Thu, 28 Feb 2013 07:56:45 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054122</link>
<description><![CDATA[superataru posted : Kool Cisco tool.<br>They added packet tracert i used to get examinations into device diagnostics page. Wonderful.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054122</guid>
<pubDate>Thu, 28 Feb 2013 02:39:55 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054074</link>
<description><![CDATA[superataru posted : <div class="bquote"><said>said by <a href="/profile/431519" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=431519');">Anav</a>:</said><p>While I search in vain for optimal MSS size, getting sidetracked in CISCO forums and very detailed and complex  Checkpoint, VPN PDF document it came to me in a vision LOL,<br><br>I brought it down to 600 from auto. I can now browse all files but streaming is still not working sometimes the opening screen shows up but is frozen.  I did not my phone switched to 4G during several attempts (from LTE).<br><br>Would SSL VPN to my shares be faster or better?????????<br> </p></div>Nice question, if you consider that i've understood 5 mins ago what you was really looking for. :-)<br><br>I got not Galaxy, and tested L2TP VPNs just with Win Clients, two Android pads by mediacom and one IPad (a customer connected with parameters i sent him, sayng "It works! i see my servers now".<br>Always rdp, web and icmp traffic, dunno about performances with media streaming from the remote (and also with or without Anti-X enabled from/to). Consider that we have not 4G atm, and a bb line with 24/8 Mbps, here, is a nice dream.<br><br>In my everyday experience i can say SSL-VPNs (only Win clients supported, if i am not wrong) has same performaces, in full tunnel.<br>"Simple" reverse proxy is very fast, instead.<br><br>Now, i am not sure, but maybe i've found a bug (or a misconfiguration of mine?): full tunnel drops if you estabilish it but not use (seems not related to user timeout). <br>Reverse proxy, you was using, keeps on on working, without problems.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28054074</guid>
<pubDate>Thu, 28 Feb 2013 01:29:08 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053812</link>
<description><![CDATA[Anav posted : While I search in vain for optimal MSS size, getting sidetracked in CISCO forums and very detailed and complex  Checkpoint, VPN PDF document it came to me in a vision LOL,<br><br>I brought it down to 600 from auto. I can now browse all files but streaming is still not working sometimes the opening screen shows up but is frozen.  I did not my phone switched to 4G during several attempts (from LTE).<br><br>Would SSL VPN to my shares be faster or better?????????]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053812</guid>
<pubDate>Wed, 27 Feb 2013 22:41:13 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053746</link>
<description><![CDATA[Anav posted : <div class="bquote"><said>said by <a href="/profile/649954" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=649954');">Brano</a>:</said><p>Interesting. On good LTE connections I can actually stream from mapped folder via VPN (tried that with ES Explorer and MX player).<br><br>Your problem seems to be like MSS size related, did you try it from elsewhere (i.e. from other than home GSM cell locations?) Try manually lowering MSS for that particular VPN connection (It's in advanced settings I believe)<br> </p></div>I will give that a try, and yes its at home. No I did not try elsewhere, what diff will it make?  My next test is to try wifi at Timmies. <br><small>--<br>Ain't nuthin but the blues! "Albert Collins". <br>Leave your troubles at the door! "Pepe Peregil" De Sevilla.  Just Don't Wifi without WPA, "Yul Brenner"<br><br><A HREF="http://www.llamaworks.ca">LlamaWorks Equipment</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053746</guid>
<pubDate>Wed, 27 Feb 2013 22:21:06 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053734</link>
<description><![CDATA[Anav posted : Last jpegs........<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053734?c=2078065&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG TITLE="56974 bytes" BORDER=0 WIDTH=583 HEIGHT=359 SRC="/r0/download/2078065~ed1f54ab5a82cc2c799d4867a8d14bfe/pc-wizard5.jpg"></A></TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053734?c=2078066&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="102656 bytes" WIDTH=600 HEIGHT=443 SRC="/r0/download/2078066.thumb600~3647e220a3dc14ae062d7e1a7f697c10/pc-wizard6.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053734</guid>
<pubDate>Wed, 27 Feb 2013 22:18:34 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053729</link>
<description><![CDATA[Anav posted : <div class="bquote"><said>said by <a href="/profile/649954" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=649954');">Brano</a>:</said><p><div class="bquote"><said>said by <a href="/profile/297212" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=297212');">Kirby Smith</a>:</said><p>We probably need flow diagrams ...<br> </p></div> </p></div>No thats very static and list oriented.  This is a dynamic tool  WITH ANIMATION, whereby you can watch the ingress and egress of traffic and its status on each step of the way.  Much better!!<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053729?c=2078058&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG TITLE="92225 bytes" BORDER=0 WIDTH=455 HEIGHT=426 SRC="/r0/download/2078058~6eaaabe72eb47d303f19fdfafb7e17cb/pc-wizard4.jpg"></A><br>Third</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053729?c=2078059&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="116949 bytes" WIDTH=600 HEIGHT=661 SRC="/r0/download/2078059.thumb600~ff71dab69d762eac97004eb7bfe8c0fc/pc-wizard3.jpg/thumb.jpg" ALT="Click for full size"></A><br>Second</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053729?c=2078060&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="71247 bytes" WIDTH=600 HEIGHT=230 SRC="/r0/download/2078060.thumb600~7211c0da94a25010a9e44f6fdb9ce98e/pc-wizard2.jpg/thumb.jpg" ALT="Click for full size"></A><br>First</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053729?c=2078061&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="150814 bytes" WIDTH=600 HEIGHT=361 SRC="/r0/download/2078061.thumb600~500da60b6f0233d5b0923a4e0d440700/pc-wizard1.jpg/thumb.jpg" ALT="Click for full size"></A><br>Overview</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053729</guid>
<pubDate>Wed, 27 Feb 2013 22:17:29 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053699</link>
<description><![CDATA[Brano posted : Interesting. On good LTE connections I can actually stream from mapped folder via VPN (tried that with ES Explorer and MX player).<br><br>Your problem seems to be like MSS size related, did you try it from elsewhere (i.e. from other than home GSM cell locations?) Try manually lowering MSS for that particular VPN connection (It's in advanced settings I believe)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053699</guid>
<pubDate>Wed, 27 Feb 2013 22:08:42 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053637</link>
<description><![CDATA[Anav posted : Yes Brano, that is the box I clicked and still no joy.   I tried both the built in browser in samsung galaxy s3 and chrome.<br><br>And by the way, ES file explorer does not do as well as X-plore.  X-explore gets me further in the menu and folder structures than ES file explorer but in the end none of them can handle the folders with large number of media files (none can stream them either of course).]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053637</guid>
<pubDate>Wed, 27 Feb 2013 21:49:42 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053521</link>
<description><![CDATA[Brano posted : <div class="bquote"><said>said by <a href="/profile/431519" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=431519');">Anav</a>:</said><p>Im assuming you mean the admin router access. Even after checking that box, I get past the certificate check stage but no router menus come up :-((<br> </p></div>I mean this<br>[att=1]<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053521?c=2078040&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG TITLE="6765 bytes" BORDER=0 WIDTH=489 HEIGHT=142 SRC="/r0/download/2078040~0de1cb8b5f7458340f4b7170903b5210/ignore_dont_fragment.png"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053521</guid>
<pubDate>Wed, 27 Feb 2013 21:14:38 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053496</link>
<description><![CDATA[Brano posted : <div class="bquote"><said>said by <a href="/profile/297212" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=297212');">Kirby Smith</a>:</said><p>We probably need flow diagrams ...<br> </p></div>How about this? ...and it's clickable too ;)<br>[att=1]<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28053496?c=2078037&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="6850 bytes" WIDTH=600 HEIGHT=114 SRC="/r0/download/2078037.thumb600~1af4c346b551176f7b2e74a9a8522669/routing_flow.png/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28053496</guid>
<pubDate>Wed, 27 Feb 2013 21:08:01 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28051640</link>
<description><![CDATA[Kirby Smith posted : We probably need flow diagrams of how ZyXEL has assembled a router out of iptables parts and their own modules to understand many questions like yours.  The more I learn about these things the more impressed I am that anyone can construct a mostly-functioning router, whether ZyXEL or the pfSense team.<br><br>Your L2TP pool is probably like a VLAN to LAN1, but there is no series L2 switch to do any discrimination.  Unless your firewall blocks 192.168.1.X from 192.168.100.X, the two "LANs" have connectivity so long as you use IP addresses between them, just as one could communicate between 192.168.1.100 and 192.168.2.200 if LANs 1 and 2 were populated.<br><br>kirby]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28051640</guid>
<pubDate>Wed, 27 Feb 2013 12:29:25 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28051325</link>
<description><![CDATA[Anav posted : Hi Kirby my comms are poorly written.<br><br>My L2TP pool is 192.168.100.1 to 192.168.100.10<br><br>My Lan is 192.168.1.33 to 192.168.1.XX<br><br>I have no LAN2 or DMZ at all with any structure such as 192.168.100.0<br><br>How does my samsung on a different LANIP pool even see my shares^^^^^^^^  Is it because at that point they are in the same boiling pot of LAN1, no traffic cops to go through (see how I dont have a clue and am reduced to simple analogies LOL)<br><br>Now obviously I am getting thru as using ES explorer I was able to map to all MY NAS boxes, and on one test, access the folders, a sub folder, open a plain text file and read the word test.  So its working. BUT BUT BUT its sheite trying to opne a folded with many media files. It cannot.  It stalls.  Obviously streaming anything is out of the question but REALLY, not enough throughput to show list of files?????  <br>(or do all apps/programs try to display thumbnails for example)<br><br>The other pizzoff is that on the admin to router routing I get connected.  I type in the LANIP of the router to access the web gui,  and I get to hey its not an official certificate side, and simply state CONTINUE and it stops there....... no getting to the official login page.....  Argggg.   <br><small>--<br>Ain't nuthin but the blues! "Albert Collins". <br>Leave your troubles at the door! "Pepe Peregil" De Sevilla.  Just Don't Wifi without WPA, "Yul Brenner"<br><br><A HREF="http://www.llamaworks.ca">LlamaWorks Equipment</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28051325</guid>
<pubDate>Wed, 27 Feb 2013 10:57:23 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28051259</link>
<description><![CDATA[Kirby Smith posted : Anav:<br><br>If I understood what you wrote, then it may be worth pointing out that if the LAN IP pool is .2 to .33, and the Samsung is given .123, and if both the LAN devices and the Samsung use a network mask of 255.255.255.0, then they should be able to see each other.<br><br>kirby]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28051259</guid>
<pubDate>Wed, 27 Feb 2013 10:39:17 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050802</link>
<description><![CDATA[Anav posted : So this seems stupid.  I have an excellent connection from my ISP, I have LTE on phone why is the throughput seemingly so limited.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050802</guid>
<pubDate>Wed, 27 Feb 2013 07:47:36 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050760</link>
<description><![CDATA[Anav posted : IM connecting from a samsung galaxy S3 not a computer.<br>To report, ES file explorer sees my shares, I can drill down to what folders are a the first level but I cannot open any lists of contents of the folders.<br>All other file explorers or media explorer-players failed to connect to the LAN at all.<br><br>IM now not convinced that I was actually accessing anything on ES explorer other than cache or already stored data.  So I cleared all and then could not add a server. (error cannot find the server).<br>Hmm somehow I was disconnected from my VPN argggg will try again disrgeard above.<br><br>No after creating a new server, it found the server could then go to the folders but would not read any content of folders.   I think it may be just timing out??<br><br>Okay, so its extremely limited in capability.  I can open folder that are small or do not have a many media files.  I can easily open a small folder and open and view a simple text file.  ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050760</guid>
<pubDate>Wed, 27 Feb 2013 07:18:41 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050724</link>
<description><![CDATA[superataru posted : Mmm.<br>Using same settings from a WinXP, or Win 7 pc?<br><br><div class="bquote"><said>said by <a href="/profile/431519" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=431519');">Anav</a>:</said><p>The problem is clear as mud.  My policy route is correct. I created an object for my LAN, i suppose I could have used the default LAN1 subnet too.   BUT BUT BUT,  the IP pool the router assigns is not the same as my LAN and thus theoretically my samsung should not be able to see didly squat even if its on the LAN.  At least now when I join my network at home via wifi it gets a LAN IP address.  <br>The other issue is that the router access (and my other policy route here works too) stops at the browser???<br>Brano I will try ES explorer and report. <br> </p></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050724</guid>
<pubDate>Wed, 27 Feb 2013 06:54:13 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050704</link>
<description><![CDATA[Anav posted : The problem is clear as mud.  My policy route is correct. I created an object for my LAN, i suppose I could have used the default LAN1 subnet too.   BUT BUT BUT,  the IP pool the router assigns is not the same as my LAN and thus theoretically my samsung should not be able to see didly squat even if its on the LAN.  At least now when I join my network at home via wifi it gets a LAN IP address.  <br>The other issue is that the router access (and my other policy route here works too) stops at the browser???<br>Brano I will try ES explorer and report. <br><small>--<br>Ain't nuthin but the blues! "Albert Collins". <br>Leave your troubles at the door! "Pepe Peregil" De Sevilla.  Just Don't Wifi without WPA, "Yul Brenner"<br><br><A HREF="http://www.llamaworks.ca">LlamaWorks Equipment</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050704</guid>
<pubDate>Wed, 27 Feb 2013 06:32:35 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050685</link>
<description><![CDATA[Brano posted : <div class="bquote"><said>said by <a href="/profile/431519" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=431519');">Anav</a>:</said><p>Also what about accessing shares?<br> </p></div>ES File Manager]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050685</guid>
<pubDate>Wed, 27 Feb 2013 06:06:16 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050338</link>
<description><![CDATA[superataru posted : Sorry, i have not understood, Anav.<br><br>(Yep, users settings have no scalability)<br><br>Now you are connected to you remote end point.<br>You should set L2TP to LAN zone firewall (i use to declare remote-not-overlapping-subnets in the rules) and destination subnet.<br>Add policy route too, without SNAT on output interface-LAN-interface.<br><br>Doesn't work?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050338</guid>
<pubDate>Tue, 26 Feb 2013 23:46:14 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050258</link>
<description><![CDATA[Anav posted : Im assuming you mean the admin router access. Even after checking that box, I get past the certificate check stage but no router menus come up :-((<br><br>Also what about accessing shares?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050258</guid>
<pubDate>Tue, 26 Feb 2013 23:19:26 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050205</link>
<description><![CDATA[Brano posted : Seen that before, check ignore don't fragment packets in global ipsec settings.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050205</guid>
<pubDate>Tue, 26 Feb 2013 22:55:44 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050164</link>
<description><![CDATA[Anav posted : I can as admin access the router somewhat.  In that I can type in the URL of the router and I get to the unkown certificate do you trust in and proceed phase but never seem to be able to enter the router (yes it switches to Https and hits the right port)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050164</guid>
<pubDate>Tue, 26 Feb 2013 22:39:22 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050040</link>
<description><![CDATA[Anav posted : SUCCESS.... my preshared keys did not match, fixed and I successfully built a tunnel and the user was accepted.  So I am halfway there.<br><br>On my samsung, how do I check which IP I have?<br>How do I see my shares?<br>Should I name the vpn connection name as the same as my LAN name?<br>Using file explorer or browser didnt seem to do the trick.<br><br>I have a connection but how to access ???<br><br>Okay couple of thoughts as well to the above dilemma...<br>I found it very annoying that i could not create a bunch of users as there is more than one of us with smartphone.  What I mean is that I could NOT apply a group name to the L2TP VPN SETTINGS for ALLOWED users ----- ONLY a single USer or ANY.  WHY is that????????<br>Do I have to create a separate rule for ever USER??<br><br>Second the IP pool I created is probably my problem,  it has a different structure than my LAN identified in the ROUTING Policys.<br>Is this right or wrong and stupid.<br>If wrong should I simply create firewall rules to allow the L2PT LAN POOL numbers access to the specific shares on the lan desired???<br><br>For ex.  <br>my lan is .1.33-xx<br>my l2tp pool is identified as .100.33-xx<br><br>Now I have no lan or dmz in my router setup for .100.0 so HOW CAN the router create a ficticious pool???????<br><br><small>--<br>Ain't nuthin but the blues! "Albert Collins". <br>Leave your troubles at the door! "Pepe Peregil" De Sevilla.  Just Don't Wifi without WPA, "Yul Brenner"<br><br><A HREF="http://www.llamaworks.ca">LlamaWorks Equipment</a></small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28050040</guid>
<pubDate>Tue, 26 Feb 2013 22:02:40 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28049996</link>
<description><![CDATA[Anav posted : Okay on VPN IPSEC CONNECTION TAB, I am using....<br>ESP-Transport - AES128 - SHA1<br><br>On VPN IPSEC GATEWAY TAB, I am using<br>Main - 3DES - SHA1 - DH2]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28049996</guid>
<pubDate>Tue, 26 Feb 2013 21:52:06 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28049949</link>
<description><![CDATA[Brano posted : Do you have encapsulation set to TRANSPORT in VPN Phase 2?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28049949</guid>
<pubDate>Tue, 26 Feb 2013 21:28:44 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28049696</link>
<description><![CDATA[Anav posted : No need to start a new thread as this one is relevant enough.<br>I am now trying to attach my smartphone via VPN to the router and the lan.   So far unsuccessful,  I have provided my logs as proof of my incompentence LOL.   Reading them the only thing that stood out was perhaps a mismatch on pre-shared key, so I will double check that and retry later.   IN the meantime if something else looks off please let me know.   Running android 4.1.1<br><small>--<br>Ain't nuthin but the blues! "Albert Collins". <br>Leave your troubles at the door! "Pepe Peregil" De Sevilla.  Just Don't Wifi without WPA, "Yul Brenner"<br><br><A HREF="http://www.llamaworks.ca">LlamaWorks Equipment</a></small><div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/28049696?c=2077775&ret=L2ZvcnVtL3IyNzk3MzkzMS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="202797 bytes" WIDTH=600 HEIGHT=190 SRC="/r0/download/2077775.thumb600~e9a8ed9dbc057b4f7a8cc9701db7a428/l2tperrorlog1.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-28049696</guid>
<pubDate>Tue, 26 Feb 2013 20:01:03 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27980511</link>
<description><![CDATA[superataru posted : Modify:<br><br>FW rules: L2TP -> LAN1]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27980511</guid>
<pubDate>Tue, 05 Feb 2013 09:25:08 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27977039</link>
<description><![CDATA[superataru posted : <div class="bquote"><said>said by <a href="/profile/649954" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=649954');">Brano</a>:</said><p>1) Upgrade to the latest FW &raquo;<A HREF="/forum/r27948198-USG-series-3.00-xxx.4-firmware-is-out-">USG series 3.00 (xxx.4) firmware is out!</A><br>2) Follow instructions here &raquo;<A HREF="/forum/r26985207-L2TP-VPN-on-USG-quick-how-to">L2TP VPN on USG - quick how-to</A><br>and update as per here &raquo;<A HREF="/forum/r27762883-L2TP-VPN-on-USG-quick-how-to-Win7-updated-">L2TP VPN on USG - quick how-to (Win7 updated)</A><br> </p></div>[SOLVED]<br><b>Most of all thanks to  Brano <A HREF="/useremail/u/649954"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A>'s HowTo(s).</b><br><br>All works fine. I have to add some interesting (surely to me) things:<br><br>(note: i created a L2TP Zone to make it easier to manage.)<br><br>- We need, working on the Internet, that WAN Iface has the Public IP (no chances behind a NAT), or bridge the Router that connects to Internet;<br>- we need to allow L2TP -> ZYWALL all services we want to allow from client to targets behind the remote USG (while i was thinking L2TP to LAN1, in my case. But, for real, L2TP should be considered Client to Client VPN, so it's correct: ZyWALL works as L2TP Client);<br><br>- Performing a ping -t command from L2TP client to remote LAN address ... i had some considerations:<br><br>- If we start client behind a remote ZyWALL that has an other IPSec VPN (not nailed up) to same destination USG:<br>---- L2TP VPNs does not cause the other Tunnel to go up, if it stars as first;<br>---- If the other Tunnel was already UP: L2TP Vpn take the traffic, and the working one stays up, but just with services related ipsec-service traffic.<br><br>Hope it could help.<br>Please, post here, if you think you i wrote incorrect things. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27977039</guid>
<pubDate>Mon, 04 Feb 2013 09:20:00 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27973942</link>
<description><![CDATA[superataru posted : <div class="bquote"><said>said by <a href="/profile/649954" onClick="this.blur(); return popup(event,'/uidpop?ajh=1&uid=649954');">Brano</a>:</said><p>1) Upgrade to the latest FW &raquo;<A HREF="/forum/r27948198-USG-series-3.00-xxx.4-firmware-is-out-">USG series 3.00 (xxx.4) firmware is out!</A><br>2) Follow instructions here &raquo;<A HREF="/forum/r26985207-L2TP-VPN-on-USG-quick-how-to">L2TP VPN on USG - quick how-to</A><br>and update as per here &raquo;<A HREF="/forum/r27762883-L2TP-VPN-on-USG-quick-how-to-Win7-updated-">L2TP VPN on USG - quick how-to (Win7 updated)</A><br> </p></div>Tnx mate.<br>Firewall already have latest firmware.<br>Going to read how-to.<br>Tnx so much.<br>I will report!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27973942</guid>
<pubDate>Sun, 03 Feb 2013 01:34:29 EDT</pubDate>
</item>

<item>
<title>Re: L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27973936</link>
<description><![CDATA[Brano posted : 1) Upgrade to the latest FW &raquo;<A HREF="/forum/r27948198-USG-series-3.00-xxx.4-firmware-is-out-">USG series 3.00 (xxx.4) firmware is out!</A><br>2) Follow instructions here &raquo;<A HREF="/forum/r26985207-L2TP-VPN-on-USG-quick-how-to">L2TP VPN on USG - quick how-to</A><br>and update as per here &raquo;<A HREF="/forum/r27762883-L2TP-VPN-on-USG-quick-how-to-Win7-updated-">L2TP VPN on USG - quick how-to (Win7 updated)</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/Re-L2TPoIPSEC-problems-27973936</guid>
<pubDate>Sun, 03 Feb 2013 01:27:06 EDT</pubDate>
</item>

<item>
<title>L2TPoIPSEC problems</title>
<link>http://www.dslreports.com/forum/L2TPoIPSEC-problems-27973931</link>
<description><![CDATA[superataru posted : Hi all, folks.<br>After some Yrs using only IPSEC/SSL, we decided to use Win7-8 / Android laptop/mobiles' clients to reach HQ, too.<br>So trying to setup L2TP VPNs on USG100 and USG200. Both 3.00(XX4). No Policies before.<br><br>It's killing me :-).<br><br>At the moment working with a W8 netbook. But also tested with W7 and Tablet with Android 4.3.X.<br><br>Remote USG----(internet)---(Router)----(ClavisterSG50)----W8Client<br><br>I got IPSEC tunnel (NAT-T)-SitetoSite USG===SG50, if i need, so UDP 500 and 4500 traffic are working fine.<br><br>I setup, as manuals say, both end points.<br> <br>I always have Error 788, back from Windows Client.<br>Looking USG logs i find that PH1 closes successfully, than USG keeps searching the right VPN connection (among those with dynamic peers) until it declares there is <br>NO PROPOSAL CHOSEN.<br><br>Had a look on: &raquo;<A HREF="/forum/r26972468-USG50-with-V3.0-L2TP-settings-lockup-Zywall">USG50 with V3.0 L2TP settings lockup Zywall.</A>.<br><br>and found that:<br>- Mode is Transport, not Tunnel;<br>- Needed a TUNNELtoZYWALL rule (allow udp 1701), as after IPSEC rules, device applies rules Tunnel-to Zywall;<br><br>From pics i observer ppl using connection with "RemoteAccess(server role)", and Italian User Guide reports Site-to-site with Dynamic Peer, and it's wrong, maybe, as it asks also for "force policy ...." flag, that exists only on "Site-to-site" and "Remote Access (Client Role)" settings.<br><br>Where should i correct something (not only in my brain ...)???<br><br>Thanks in advance.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/L2TPoIPSEC-problems-27973931</guid>
<pubDate>Sun, 03 Feb 2013 01:20:43 EDT</pubDate>
</item>

</channel>
</rss>
