Господа прошу вашей помощи, не могу из винды приконектится к циске по L2TP + Ipsec стандартным клиентом. Ниже привожу конфиг естественно только то что касается VPNaaa new-model
!
!
!
aaa authentication login default local
aaa authentication ppp default local
!
!
aaa session-id common
vpdn-group L2TP
! Default L2TP VPDN group
accept-dialin
protocol l2tp
virtual-template 1
l2tp security crypto-profile L2TP
no l2tp tunnel authentication
!
username profgcc password 0 my_password
crypto isakmp policy 100
encr 3des
authentication pre-share
group 2
crypto isakmp key mykey address 0.0.0.0 0.0.0.0
!
!
crypto ipsec transform-set L2TP esp-3des esp-sha-hmac
mode transport
!
crypto map L2TP 100 ipsec-isakmp profile L2TP
set transform-set L2TP
!
!
!
!
!
interface Loopback1
ip address 172.16.0.254 255.255.255.0
!
interface GigabitEthernet0/0.2
description ADMINISTRATIVE_INTERFACE
encapsulation dot1Q 3
ip address 10.0.1.1 255.255.255.0
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
crypto map L2TP
!
interface Virtual-Template1
ip unnumbered Loopback1
peer default ip address pool mypool
ppp authentication ms-chap-v2 callin
!
ip local pool mypool 172.16.0.1 172.16.0.253
C таким конфигом нихрена не работает debug ppp nego
Jul 30 06:01:58.707: ppp187 PPP: Send Message[Dynamic Bind Response]
Jul 30 06:01:58.707: ppp187 PPP: Using vpn set call direction
Jul 30 06:01:58.707: ppp187 PPP: Treating connection as a callin
Jul 30 06:01:58.707: ppp187 PPP: Session handle[710000D3] Session id[187]
Jul 30 06:01:58.707: ppp187 PPP: Phase is ESTABLISHING, Passive Open
Jul 30 06:01:58.707: ppp187 LCP: State is Listen
Jul 30 06:02:00.695: ppp187 LCP: Timeout: State Listen
Jul 30 06:02:00.695: ppp187 LCP: O CONFREQ [Listen] id 1 len 15
Jul 30 06:02:00.695: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:00.695: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:02.711: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:02.711: ppp187 LCP: O CONFREQ [REQsent] id 2 len 15
Jul 30 06:02:02.711: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:02.711: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:04.727: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:04.727: ppp187 LCP: O CONFREQ [REQsent] id 3 len 15
Jul 30 06:02:04.727: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:04.727: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:06.743: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:06.743: ppp187 LCP: O CONFREQ [REQsent] id 4 len 15
Jul 30 06:02:06.743: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:06.743: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:08.759: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:08.759: ppp187 LCP: O CONFREQ [REQsent] id 5 len 15
Jul 30 06:02:08.759: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:08.759: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:10.775: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:10.775: ppp187 LCP: O CONFREQ [REQsent] id 6 len 15
Jul 30 06:02:10.775: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:10.775: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:12.791: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:12.791: ppp187 LCP: O CONFREQ [REQsent] id 7 len 15
Jul 30 06:02:12.791: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:12.791: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:14.807: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:14.807: ppp187 LCP: O CONFREQ [REQsent] id 8 len 15
Jul 30 06:02:14.807: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:14.807: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:16.823: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:16.823: ppp187 LCP: O CONFREQ [REQsent] id 9 len 15
Jul 30 06:02:16.823: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:16.823: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:18.839: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:18.839: ppp187 LCP: O CONFREQ [REQsent] id 10 len 15
Jul 30 06:02:18.839: ppp187 LCP: AuthProto MS-CHAP-V2 (0x0305C22381)
Jul 30 06:02:18.839: ppp187 LCP: MagicNumber 0x25C136B3 (0x050625C136B3)
Jul 30 06:02:20.855: ppp187 LCP: Timeout: State REQsent
Jul 30 06:02:20.855: ppp187 LCP: O TERMREQ [REQsent] id 10 len 4
Jul 30 06:02:20.855: ppp187 PPP: Phase is TERMINATING
Jul 30 06:02:20.855: ppp187 LCP: State is Listen
Jul 30 06:02:20.855: ppp187 PPP: Sending Acct Event[Down] id[D1]
Jul 30 06:02:20.855: ppp187 LCP: State is Closed
Jul 30 06:02:20.855: ppp187 PPP: Phase is DOWN
Jul 30 06:02:20.855: ppp187 PPP: Send Message[Disconnect]
При этом при вот таком конфиге все норм
aaa new-model
!
!
!
aaa authentication login default local
aaa authentication ppp default local
!
!
aaa session-id common
vpdn-group L2TP
! Default L2TP VPDN group
accept-dialin
protocol l2tp
virtual-template 1
no l2tp tunnel authentication
!
username profgcc password 0 my_password
crypto isakmp policy 100
encr 3des
authentication pre-share
group 2
crypto isakmp key mykey address 0.0.0.0 0.0.0.0
!
!
crypto ipsec transform-set L2TP esp-3des esp-sha-hmac
mode transport
!
crypto map L2TP 100 ipsec-isakmp
set peer 10.0.5.51
set transform-set L2TP
match address 101
!
!
!
!
!
interface Loopback1
ip address 172.16.0.254 255.255.255.0
!
interface GigabitEthernet0/0.2
description ADMINISTRATIVE_INTERFACE
encapsulation dot1Q 3
ip address 10.0.1.1 255.255.255.0
ip flow ingress
ip flow egress
ip nat inside
ip virtual-reassembly
crypto map L2TP
!
interface Virtual-Template1
ip unnumbered Loopback1
peer default ip address pool mypool
ppp authentication ms-chap-v2 callin
!
ip local pool mypool 172.16.0.1 172.16.0.253
access-list 101 permit udp host 10.0.1.1 eq 1701 host 10.0.1.51 eq 1701