Gentoo Archives: gentoo-user

From: covici@××××××××××.com
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] problem with l2tp-isec
Date: Thu, 19 Dec 2013 15:28:49
Message-Id: 13686.1387466921@ccs.covici.com
In Reply to: Re: [gentoo-user] problem with l2tp-isec by Mick
1 Thanks -- I followed the wrong wiki, I will see if there is much
2 difference and check the debugging.
3
4 Thanks.
5
6 Mick <michaelkintzios@×××××.com> wrote:
7
8 > On Thursday 19 Dec 2013 14:27:28 covici@××××××××××.com wrote:
9 > > Hi. I am trying to configure l2tp-isec to a server and although it
10 > > works in Winblows, whenever I put c followed by the name, it times out.
11 > > I am not seeing any particular bad messages, except that netlink says 20
12 > > bytes left over after parsing attributes, but there seems to be no
13 > > solution to that. I am using openswan plus xl2tp.
14 > >
15 > >
16 > > How can I troubleshoot this, or should I post my configs here?
17 > >
18 > > Thanks in advance for any suggestions.
19 >
20 >
21 > Have you followed suggestions relevant to openswan and xl2tpd here?
22 >
23 > http://wiki.gentoo.org/wiki/IPsec_L2TP_VPN_server
24 >
25 > Increase the verbosity of the openswan debugging to see if ipsec is
26 > established, or why it fails.
27 >
28 > If the ipsec association is established, then check the x2ltp configuration
29 > and set 'debug tunnel = yes' to get more information from it, or start it as
30 > 'xl2tpd -D' to get some useful information until you get it going.
31 >
32 >
33 > However, if you are using Windows >=7 then it may be better to install and run
34 > StrongSwan with IKEv2 on Linux, which MSWindows can now support natively and
35 > do away with L2TP all together. Openswan also supports IKEv2.
36 >
37 > --
38 > Regards,
39 > Mick
40
41 --
42 Your life is like a penny. You're going to lose it. The question is:
43 How do
44 you spend it?
45
46 John Covici
47 covici@××××××××××.com