Community discussions

MikroTik App
 
nuskope
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 73
Joined: Wed Oct 22, 2008 3:11 pm
Location: Adelaide, South Australia
Contact:

L2TP Tunnel Authentication (ADSL with Mikrotik LNS)

Mon Jul 09, 2012 10:37 am

Hi All,

With some Googleing, and coming though the forum archives i have failed to find much information on L2TP Tunnel Authentication.

Basically we are about to start offing ADSL services, in addition to our wireless ones, And using the same LNS setup would be preferred, as all of our systems are built around Mikrotik.

however, the Wholesale provider, dumps the service off to us as a l2tp tunnel, that will then pass over the PPPOE connections.

want i want to know:

is l2tp tunnel authentication possible?
is it possible for multiple (without limit) l2tp connections from the same LAC?
 
jandafields
Forum Guru
Forum Guru
Posts: 1515
Joined: Mon Sep 19, 2005 6:12 pm

Re: L2TP Tunnel Authentication (ADSL with Mikrotik LNS)

Mon Jul 09, 2012 10:05 pm

Hi All,

With some Googleing, and coming though the forum archives i have failed to find much information on L2TP Tunnel Authentication.

Basically we are about to start offing ADSL services, in addition to our wireless ones, And using the same LNS setup would be preferred, as all of our systems are built around Mikrotik.

however, the Wholesale provider, dumps the service off to us as a l2tp tunnel, that will then pass over the PPPOE connections.

want i want to know:

is l2tp tunnel authentication possible?
is it possible for multiple (without limit) l2tp connections from the same LAC?
Yes, l2tp has a username and password and optional encryption. PPP -> SECRETS (if you are the server) and PPP -> INTERFACE, NEW PPP CLIENT (if you are the client).

You can control whether or not you allow multiple simultaneous connections from the same username (in PPP -> PROFILE).
 
nuskope
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 73
Joined: Wed Oct 22, 2008 3:11 pm
Location: Adelaide, South Australia
Contact:

Re: L2TP Tunnel Authentication (ADSL with Mikrotik LNS)

Tue Jul 10, 2012 6:35 am

The problem i am having, i see the l2tp request come through. but the it stops and fails before it gets to the part where it tries to Auth agaisnt the mikrotik ppp secrets.
12:58:25 l2tp,debug,packet     rcvd control message from 10.10.10.1:1701 
12:58:25 l2tp,debug,packet     tunnel-id=26, session-id=0, ns=1, nr=1 
12:58:25 l2tp,debug,packet     (M) Message-Type=StopCCN 
12:58:25 l2tp,debug,packet     (M) Result-Code=2 
12:58:25 l2tp,debug,packet      Error-Code=6 
12:58:25 l2tp,debug,packet      Error-Message="Tunnel auth failed for LNS-1@Primus, no chal resp" 
12:58:25 l2tp,debug,packet     105(vendor-id=9)=0x00:01 
12:58:25 l2tp,debug,packet     (M) Assigned-Tunnel-ID=23911 12:58:25 l2tp,debug,packet     sent control message (ack) to 10.10.10.1:1701 
12:58:25 l2tp,debug,packet     tunnel-id=23911, session-id=0, ns=1, nr=2 
12:58:25 l2tp,debug tunnel     26 entering state: dead 
I can l2tp in from another mikrotik with no issues at all.
Its just not opening the LAC
 
jandafields
Forum Guru
Forum Guru
Posts: 1515
Joined: Mon Sep 19, 2005 6:12 pm

Re: L2TP Tunnel Authentication (ADSL with Mikrotik LNS)

Tue Jul 10, 2012 3:25 pm

Oh, I see what you are asking now.

Mikrotik doesn't currently support LAC. See this topic: http://forum.mikrotik.com/viewtopic.php?f=1&t=26698
 
nuskope
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 73
Joined: Wed Oct 22, 2008 3:11 pm
Location: Adelaide, South Australia
Contact:

Re: L2TP Tunnel Authentication (ADSL with Mikrotik LNS)

Thu Jul 12, 2012 5:17 pm

Yes it would seem as though Mikrotik alone at this time cannot do the task.

So We put a Cisco in there, and have it doing the LAC, and passing though the end l2TP-ppp connections.

at this time i have only tested one line, but seems to be working fine. Allowing us to use all our Mikrotik API's ect on our LNS and our radius.

If anyone wants the conf of the cisco just let me know.

mike
 
hedele
Member
Member
Posts: 338
Joined: Tue Feb 24, 2009 11:23 pm

Re: L2TP Tunnel Authentication (ADSL with Mikrotik LNS)

Tue Oct 09, 2012 11:11 pm

Hi,

I guess you maybe know that - Routerboards can accept L2TP tunneled DSL connections as LNS if no tunnel authentication is required.
If the LAC is a Cisco router - you have to use "no lt2p tunnel authentication" in the vpdn group.

Relayed ppp sessions will then show up as L2TP server interface on the Routerboard and can be authenticated against PPP secrets or Radius.

Who is online

Users browsing this forum: bananaboy1101, johnymalina, phcooper, rizan, sindy and 40 guests