This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

L2TP remote access issues

Hi everyone,

I am migrating my setup from Sophos UTM to Sophos Firewall XG and now I've hit an issue with the L2TP remote VPN access. Before I share any configuration details (these are all fairly vanilla as I am not trying to do anything exotic) let me share what I see in the charon.log

ALERT: received IKE message with invalid SPI 

Googling this found some hints but nothing too concrete regarding my config. What should the values of remote ID and local ID be? I chose IP address for both and I put the IP of the WAN interface that gets the incoming connection. The policy I am using is the DefaultL2TP policy unmodified.

Any ideas?

Thank you!



This thread was automatically locked due to age.
  • Forgot to mention that the client I am using to connect is just an Android phone. I am used a preshared secret key and the client setup is the same as with the Sophos UTM days which was working fine. At the end of the day, there isn't much you can modify from the client side other than the secret key and the username and password.