Question VPN L2TP/IPSec - can't connect

Currently reading
Question VPN L2TP/IPSec - can't connect

295
32
NAS
DS1019+ DSM6
Operating system
  1. Windows
Mobile operating system
  1. iOS
i have enabled L2TP/IPSec, configured as required, but can't seem to get a device to connect to it.

1701, 500. 4500 UDP open and pointing to NAS on the router (EdgeRouter).

on android phone, added VPN L2TP/IPSec PSK.
entered IP
entered IPSec preshared key
entered username/password (of allowed user)

clicked connect, attemped then fails.

check the log on the NAS, no log entries to show any attempted connection.
NAS firewall not currently enabled.

any ideas what the issue is?

DS1019+ DSM 6.2.2-24922 Update 4
 
i'll need to wait until i'm home to try a LAN-LAN connection.
there are no IPs in the block list.
 
The other obvious question: is the Android device directly connected to the Internet (mobile data) or from inside a third party WiFi network. If it's the latter then there could be access controls to block VPNs and other traffic types.
 
android device is direct connected to internet (4G).
 
OK an inconclusive test.
at home connected to WIFI (same IP range as NAS).
changed VPN client to use local LAN IP of NAS rather than external IP.

attempt 1 - failed
attempt 2 - failed
attempt 3 - success
attempt 4 - failed
attempt 5 failed

also tried it using the external IP whilst still connected to local WIFI

attempt 1 - failed
attempt 2 - success
attempt 3 - failed
attempt 4 - failed
attempt 5 failed
 
OK an inconclusive test.
at home connected to WIFI (same IP range as NAS).
changed VPN client to use local LAN IP of NAS rather than external IP.

attempt 1 - failed
attempt 2 - failed
attempt 3 - success
attempt 4 - failed
attempt 5 failed

also tried it using the external IP whilst still connected to local WIFI

attempt 1 - failed
attempt 2 - success
attempt 3 - failed
attempt 4 - failed
attempt 5 failed
Results same with a different device apart from that android device?
 
just had a thought. my router (Edgerouter) has OpenVPN built in, i wonder if it's a port clash?
although OpenVPN shouldn't be using the same ports.
 
Router might also need to be specifically configured to pass through VPN traffic (and not merely port forward). This is typically found under a "security" tab or similar. For example, on the Synology router, it looks like this:

1578434156132.png
 
Router might also need to be specifically configured to pass through VPN traffic (and not merely port forward). This is typically found under a "security" tab or similar. For example, on the Synology router, it looks like this:

but then surely it would fail 100% of the time?
the fact i can connect like 20% of the time suggests that the router is already allowing the traffic thru.
 
No, both your "successful" tests were from inside your own LAN. The fact that you were pointIng at the WAN address didn't make a difference. It's not like the packets went out onto the internet and then came back in.
 
i did the same tests on 4G though, and got the same success rate.
 
Check in your Edge Router for L2TP
Firewall:
enable Protocol 50, to be sure - not Port 50
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

  • Question
Can't offer any solution, but can you try a different VPN type? OpenVPN? Is your router on the latest...
Replies
2
Views
667
  • Question
The best way to set up a VPN client on a Synology RT2600ac router is to use the VPN Plus Server feature...
Replies
2
Views
618
Did you try to directly connect using the NAS's LAN IP? And that also fails? How exactly are you...
Replies
3
Views
378
That would be an option as well ofc. Still depends on the router and how much OP has control over it, but...
Replies
5
Views
577
No VPN client setup on the router is "one for all", not SSID specific.
Replies
1
Views
541
Update: ISP changed IP address and other issues on the router, problem solved.
Replies
6
Views
1,011
Thank you for your help ! Doesn't work with incognito, weird. At least I have other solutions....
Replies
10
Views
677

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Back
Top