Solved

Outgoing L2TP VPN doesn't work through one of two LANs on same router

Posted on 2014-03-25
4
684 Views
Last Modified: 2014-04-12
We have a Draytek 2960 router running the latest firmware (1.0.7.1).  We have a remote site that we connect to using an L2TP VPN.  This works fine from elsewhere (3G, home, someone else's Wi-Fi, etc.) and from our guest network.  It won't work though from our main corporate network (we see error 789).  Switch back to 3G or the guest network and we're on.

The guest network has DHCP from the router, and a firewall rule blocking access to our other internal networks.  The corporate network has DHCP from the SBS2011 server, and unrestricted outgoing access in the firewall.

What setting should I change in order to rectify this?  Thanks in advance for any suggestions.
0
Comment
Question by:David Haycox
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
4 Comments
 
LVL 17

Expert Comment

by:TimotiSt
ID: 39958575
Looks like Draytek's have some issues with L2TP.
The latest-greatest 1.0.8 firmware is out for the 2960, it mentions some L2TP fixes, you could try your luck with it.

Tamas
Vigor2960-v1.0.8-release-note.pdf
0
 
LVL 1

Author Comment

by:David Haycox
ID: 39958599
Thanks, will give it a try.  Only just upgraded it to 1.0.7.1 - good to see the router is still under active development though.
0
 
LVL 1

Accepted Solution

by:
David Haycox earned 0 total points
ID: 39983630
The firmware update didn't make any difference, however I traced the problem to a setting on a switch - an HP Procurve HP 1810-48G (J9660).  Disabling "Auto DoS" fixed it.
0
 
LVL 1

Author Closing Comment

by:David Haycox
ID: 39995851
Found solution myself.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
replacing 2811 to ISR 4331 2 48
Standard Naming Convention Policy - Servers, Routers, Switches, Firewalls 3 78
Router Question 12 75
ASA5510 Blocking a Wanted Website/Host 9 48
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question