开发者社区> 问答> 正文

L2TP配置

配置L2TP服务端,按照阿里给的配置脚本(l2tp.sh),完整的执行了一遍。
但是,无论手机还是PC端都无法正常连接,折腾了好几天了,头发都白了。


1、ipsec verify正常:

Checking your system to see if IPsec got installed and started correctly:
Version check and ipsec on-path                                 [OK]
Linux Openswan U2.6.38/K3.10.0-514.26.2.el7.x86_64 (netkey)
Checking for IPsec support in kernel                            [OK]
SAref kernel support                                           [N/A]
NETKEY:  Testing XFRM related proc values                      [OK]
        [OK]
        [OK]
Hardware RNG detected, testing if used properly                 [OK]
Checking that pluto is running                                  [OK]
Pluto listening for IKE on udp 500                             [OK]
Pluto listening for NAT-T on udp 4500                          [OK]
Checking for 'ip' command                                       [OK]
Checking /bin/sh is not /bin/dash                               [OK]
Checking for 'iptables' command                                 [OK]
Opportunistic Encryption Support                                [DISABLED]


2、tail -f /var/log/secure,看到有报错如下:

Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-06] meth=111, but already using method 115
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-05] meth=110, but already using method 115
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-04] meth=109, but already using method 115
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-03] meth=108, but already using method 115
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02] meth=107, but already using method 115
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: received Vendor ID payload [draft-ietf-ipsec-nat-t-ike-02_n] meth=106, but already using method 115
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: ignoring Vendor ID payload [FRAGMENTATION 80000000]
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: received Vendor ID payload [Dead Peer Detection]
Nov 16 22:40:42 izj6c6h25ghj5n6vo0emwnz pluto[3070]: packet from 221.222.9.47:500: initial Main Mode message received on 172.31.232.230:500 but no connection has been authorized with policy=PSK


尝试了很多方法,无论如何都无法解决,愁死我了!哪位大师可否指点一下?
不胜感激!!

展开
收起
camore 2017-11-16 22:58:02 4586 0
2 条回答
写回答
取消 提交回答
  • ReL2TP配置
    一般都是安全组和iptables的问题, 4500/500/1701 udp端口允许

    然后就能连上,  不过连上不一定能上网, 解决方式如下

    vi /etc/sysconfig/iptables

    #-A POSTROUTING -s 192.168.8.0/24 -j SNAT -o eth0 --to-source 47.52.xxx.xxx(外网IP)
    -A POSTROUTING -s 192.168.8.0/24 -o eth0 -j MASQUERADE

    service iptables restart
    2017-11-30 13:50:34
    赞同 展开评论 打赏
  • 旺旺:nectar2。
    版主回复:

    请问您的ECS实例是在哪个地域的呢?
    2017-11-17 09:11:14
    赞同 展开评论 打赏
问答排行榜
最热
最新

相关电子书

更多
低代码开发师(初级)实战教程 立即下载
冬季实战营第三期:MySQL数据库进阶实战 立即下载
阿里巴巴DevOps 最佳实践手册 立即下载