Hello,
I'm trying to setup a site-to-site VPN and a L2TP server between 2 EdgeRouter.
I have already set-up a L2TP server and it's working perfectly, however my site-to-site VPN isn't working.
Configuration on R1
auto-firewall-nat-exclude enable esp-group FOO0 { proposal 1 { encryption aes128 hash sha1 } } ike-group FOO0 { proposal 1 { dh-group 14 encryption aes128 hash sha1 } } ipsec-interfaces { interface eth0 } nat-networks { allowed-network 0.0.0.0/0 { } } nat-traversal enable site-to-site { peer 0.0.0.0 { authentication { mode pre-shared-secret pre-shared-secret XXXXXXXXXXX } connection-type respond description "VPN IPsec " ike-group FOO0 local-address X.X.X.X tunnel 1 { esp-group FOO0 local { prefix 192.168.226.0/22 } remote { prefix 192.168.1.0/24 } } } } [edit] admin@recherche# show vpn l2tp remote-access authentication { local-users { username test1 { password XXXXXXXX } username test2 { password XXXXXXXX } } mode local } client-ip-pool { start 192.168.226.0 stop 192.168.226.9 } dns-servers { server-1 8.8.8.8 server-2 8.8.4.4 } ipsec-settings { authentication { mode pre-shared-secret pre-shared-secret XXXXXXXX } } mtu 1492 outside-address X.X.X.X
Configuration on R2 :
auto-firewall-nat-exclude enable esp-group FOO0 { proposal 1 { encryption aes128 hash sha1 } } ike-group FOO0 { proposal 1 { dh-group 14 encryption aes128 hash sha1 } } ipsec-interfaces { interface eth1 } nat-networks { allowed-network 0.0.0.0/0 { } } nat-traversal enable site-to-site { peer X.X.X.X { authentication { mode pre-shared-secret pre-shared-secret XXXXXXXXXXXX } connection-type initiate description "VPN" ike-group FOO0 local-address any tunnel 1 { esp-group FOO0 local { prefix 192.168.1.0/24 } remote { prefix 192.168.226.0/22 } } } }
I don't know what is wrong. When I check the logs, I have the following lines :
Jan 1 07:09:10 00[DMN] Starting IKE charon daemon (strongSwan 5.2.2, Linux 3.10.20-UBNT, mips64) Jan 1 07:09:11 07[IKE] <peer-X.X.X.X-tunnel-1|1> initiating Main Mode IKE_SA peer-X.X.X.X-tunnel-1[1] to X.X.X.X
When i type show vpn ipsec status :
Looks like IPsec is running but IKE exchange is not working... Anyone has the same issue ?
Thanks,