LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-03-2020, 09:18 AM   #1
mstjohn1974
Member
 
Registered: Sep 2005
Location: Albuquerque
Distribution: Ubuntu
Posts: 33

Rep: Reputation: 5
Question Meraki L2TP VPN Setup issue on Fedora 32 (KDE)


I am facing an issues with setting up a Meraki L2TP VPN connection from my Fedora 32 KDE Edition. We use a Pre-shared Key and not a certificate. Windows, Mac and Android devices connect just fine.

I have the following IPsec Settings:
- Enabled IPsec tunnel to L2TP host
- Enter Pre-shared key we set on our MX64
- Phase 1: 3des-sha1-modp2048
- Phase 2: 3des-sha1
- Unchecked "Enforce UDP encapsulation

The following PPP Settings:
- Checked only PAP authentication method
- Checked the following Compressions:
-- Allow BSD compression
-- Allow Deflate compression
-- Allow TCP header compression
-- Use protocol field compression negotiation
-- Use Address/Control compression
- Set MRU to 1400
- Set MTU to 1400

When I try to establish a VPN connection to my Meraki MX64 I get the following event log:
Sep 3 08:06:59 Non-Meraki / Client VPN negotiation msg: phase1 negotiation failed.
Sep 3 08:06:59 Non-Meraki / Client VPN negotiation msg: failed to pre-process ph1 packet (side: 1, status 1).
Sep 3 08:06:59 Non-Meraki / Client VPN negotiation msg: failed to get valid proposal.
Sep 3 08:06:59 Non-Meraki / Client VPN negotiation msg: no suitable proposal found.
Sep 3 08:06:55 Non-Meraki / Client VPN negotiation msg: phase1 negotiation failed.

Does anybody setup successfully a Meraki L2TP VPN connection on Fedora?
 
Old 09-03-2020, 09:59 AM   #2
PROBLEMCHYLD
Senior Member
 
Registered: Apr 2015
Posts: 1,201

Rep: Reputation: Disabled
Try using

- Phase 1:
Code:
aes256-sha2_256-modp2048,aes256-sha2_256-modp1536,aes256-sha2_256-modp1024,aes256-sha1-modp2048,aes256-sha1-modp1536,aes256-sha1-modp1024,aes256-sha1-ecp384,aes128-sha1-modp1024,aes128-sha1-ecp256,3des-sha1-modp2048,3des-sha1-modp1024
- Phase 2:
Code:
aes256-sha1,aes128-sha1,3des-sha1
 
Old 09-03-2020, 10:39 AM   #3
mstjohn1974
Member
 
Registered: Sep 2005
Location: Albuquerque
Distribution: Ubuntu
Posts: 33

Original Poster
Rep: Reputation: 5
Just did still getting the following

Sep 3 09:37:01 Non-Meraki / Client VPN negotiation msg: failed to pre-process ph1 packet (side: 1, status 1).
Sep 3 09:37:01 Non-Meraki / Client VPN negotiation msg: failed to get valid proposal.
Sep 3 09:37:01 Non-Meraki / Client VPN negotiation msg: no suitable proposal found.
Sep 3 09:36:59 Non-Meraki / Client VPN negotiation msg: phase1 negotiation failed.
 
Old 09-03-2020, 12:07 PM   #4
PROBLEMCHYLD
Senior Member
 
Registered: Apr 2015
Posts: 1,201

Rep: Reputation: Disabled
Try using MSCHAPv2 only with Point-to-Point Encryption (MPPE) and allow stateful encryption with all other options unchecked.
 
Old 09-03-2020, 12:20 PM   #5
mstjohn1974
Member
 
Registered: Sep 2005
Location: Albuquerque
Distribution: Ubuntu
Posts: 33

Original Poster
Rep: Reputation: 5
Sorry but I get the same errors
 
Old 09-03-2020, 12:24 PM   #6
PROBLEMCHYLD
Senior Member
 
Registered: Apr 2015
Posts: 1,201

Rep: Reputation: Disabled
Do you have a firewall on your system?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
L2TP/IPSec VPN Setup on Centos 6 ahm375 Linux - Networking 3 08-02-2014 11:03 AM
Configuring squid server for caching using Arch and Meraki digitania Linux - Networking 1 09-18-2013 02:19 AM
Setup a L2TP VPN server freefall12 Linux - Networking 0 04-21-2013 09:44 AM
xl2tpd / ppp setup for an IPsec+L2TP VPn cchildress Linux - Networking 1 02-16-2013 06:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration