This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP with Certificate and RADIUS

Hi everyone,

i have the following sceanrio. 

UTM with Firmware 9.502-4, Windows Server 2012 R2 with Network Policy Role and Windows 10 Client

At first i have generated a certificate under Remote Access -> Certificate Management with the Name vpn. 

I configured a L2TP over IPSec configuration with X.509 Certificate Check and selct the certificate vpn and i select RADIUS for my users. Then i downloaded the certificate vpn and installed to the Windows 10 Client. But in the configuration tab of the vpn connection, i can't select the certificate. Is thos correct? Do i have to distribute only this certificate to my users? Or have anyone his own certificate?

If i start the Connection the Client try for while, but the i get the error message, that a failure during the security Exchange with the remote Computer. At the NPS i see the request, but the username is absolutly wrong (Domain\admin) and worng NAS-Type. I have configured l2tp, but i saw webadmin

In the UTM logfile i found:

[..]
2017:08:04-10:40:12 vpn pluto[5409]: | certificate is valid
2017:08:04-10:40:12 vpn pluto[5409]: | authcert list locked by 'verify_x509cert'
2017:08:04-10:40:12 vpn pluto[5409]: | issuer cacert found
[..]

2017:08:04-10:40:12 vpn pluto[5409]: | certificate signature is valid
2017:08:04-10:40:12 vpn pluto[5409]: | authcert list unlocked by 'verify_x509cert'
2017:08:04-10:40:12 vpn pluto[5409]: | reached self-signed root ca with a path length of 0
2017:08:04-10:40:12 vpn pluto[5409]: | Public key validated
2017:08:04-10:40:12 vpn pluto[5409]: | Notify Message Type: AUTHENTICATION_FAILED
2017:08:04-10:40:12 vpn pluto[5409]: | removing 12 bytes of padding
2017:08:04-10:40:12 vpn pluto[5409]: "L_for admin"[11] 80.187.102.188:2710 #8: ignoring informational payload, type AUTHENTICATION_FAILED

 [..]

Do i think wrong? Or what is my mistake?

Best regards and thank you very much,

Stefan



This thread was automatically locked due to age.