Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

XG v18 and L2TP/RADIUS Authentification

Hallo Community,

 

I want to setup a L2TP Connection with RADIUS Authentication as described here: https://community.sophos.com/kb/en-us/132293

When I configure the L2TP connection bon an iPhone or use the “Test Connection” the only reaction is: “Authentication failed”.

When I do a LDAP-Connection (with User Portal) the Authentification is successful.

Has anybody a working setup?

 

Thanks,

Ben



This thread was automatically locked due to age.
  • Hey Ben,

     

    I had a similar issue also in V17.5. My issue was when I used LDAP / Windows 10 / L2TP I needed to enable PAP in both the XG VPN and Windows 10 VPN adaptor settings.

    This article shows you the table and how to change it to PAP

    https://community.sophos.com/kb/en-us/123169

     

    Then in the Windows 10 VPN Adaptor open Properties and Security and enable PAP

     

    Then users can Authenticate L2TP with AD Credentials.

    It might be the same for you with the RADIUS and the XG talking to AD.

     

    This might be worth a try to see if it fixes your issue also?

     

    Sophos XG 450 (SFOS 18.5.1 MR-1)

    Sophos R.E.D 50 x 2

    Always configuring new stuff.....

  • Hi Ben,

    This should all work fine.

    If you are using the XG builtin "Test Connection" button then you must have PAP enabled on your NPS policy.  This is due to the fact that the XG RADIUS client sends the connection test in PAP.

    For the iPhone, you must remember to set a "local ID" on the L2TP connection you have set up.

    Have you tested with any other device?  Has this device been successful?

    You could run a packet capture on the XG and review it in Wireshark to see what the RADIUS server is sending the XG.  If the RADIUS server is sending the XG "Access Accept" then we need to look at the XG's access_server.log file in the "Advanced Console".  If the XG shows successful but the iPhone is not allowing the connection, then we need to dig from the iPhone side.  However at that point, if you are a paid user, I would suggest opening a case with support.

    Let us know how it goes with the troubleshooting.

    Thanks!

    KingChris
    Community Support | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • Hello KingChris,

    Now I'm one step further. I have configured the NPS server according to these instructions:
    community.sophos.com/.../132293

    When I press the "test Connection" button in the RADIUS server configuration, I get a: "Device-RADIUS server connectivity test was successful". So far, so good.

    In the next step I take a Windows 10 client and set up a L2TP VPN connection. After I have entered my username and password, I get a message that the username or password is wrong. If I now look at the NPS server in the log, I see that the wrong "Connection Request Policy" is being used.
    Do you have an explanation what makes the XG test different from the "real" VPN connection?

    Thanks,

    Ben

    If a post solves your question please use the 'Verify Answer' button.

  • Hello Community,

    I checked the RADIUS requests with Wireshark. The first one is the request when I click on "Test Connection". All parameters in the request are as described in the KB article and the test is OK. The second screenshot is when I try to establish a L2TP VPN connection with the Windows Client. It is completely different from the first one.

     

    "Test Connection":

    Windows L2TP Client:

    Has anybody a working setup with Sophos XG v18, RADIUS (Windows NPS-Server) and a Windows 10 Client?

     

    Thanks,

    Ben

    If a post solves your question please use the 'Verify Answer' button.

  • Hello Community,

    I have made the settings on the NPS server as shown in the dump This makes it possible to perform RADIUS authentication. 

    Ben

    If a post solves your question please use the 'Verify Answer' button.