• 全部
  • 经验案例
  • 典型配置
  • 技术公告
  • FAQ
  • 漏洞说明
  • 全部
  • 全部
  • 大数据引擎
  • 知了引擎
产品线
搜索
取消
案例类型
发布者
是否解决
是否官方
时间
搜索引擎
匹配模式
高级搜索

mac 笔记本通过 l2tp 无法连接VPN

4天前提问
  • 0关注
  • 0收藏,100浏览
粉丝:0人 关注:0人

问题描述:

mac 笔记本通过 l2tp 无法连接VPN

组网及组网描述:

<msr3600>system-view

System View: return to User View with Ctrl+Z.

[msr3600]di

[msr3600]dis

[msr3600]display cu

[msr3600]display current-configuration

#

 version 7.1.064, Release 6728P26

#

 sysname msr3600

#

 clock timezone beijing add 08:00:00

#

wlan global-configuration

#

 telnet server enable

 telnet server acl 3222

#

 undo resource-monitor output syslog snmp-notification netconf-event

#

 qos carl 1 source-ip-address object-group ⚌ͨר⚌⚌-⚌û⚌⚌⚌⚌⚌ per-address

 qos carl 2 destination-ip-address object-group ⚌ͨר⚌⚌-⚌û⚌⚌⚌⚌⚌ per-address

 qos carl 3 source-ip-address object-group ddns-⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌

 qos carl 4 destination-ip-address object-group ddns-⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌

 qos carl 5 source-ip-address object-group ⚌⚌⚌ż⚌⚌⚌1000M-⚌û⚌⚌⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌

 qos carl 6 destination-ip-address object-group ⚌⚌⚌ż⚌⚌⚌1000M-⚌û⚌⚌⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌

#

 security-zone intra-zone default permit

#

 security-policy disable

#

track 1 nqa entry admin liantong reaction 1

#

 ip pool l2tp1 172.16.110.2 172.16.110.254

#

 dialer-group 1 rule ip permit

 dialer-group 2 rule ip permit

 dialer-group 3 rule ip permit

#

 ip ttl-expires enable

#

 ip load-sharing mode per-flow global

#

nat address-group 1

 address 192.168.8.1 192.168.8.1

#

 dns server 202.103.24.68

 dns server 218.104.111.122

 dns server 223.5.5.5

#

 system-working-mode standard

 password-recovery enable

#

vlan 1

#

object-group ip address ddns-⚌⚌⚌

 0 network range 172.16.3.1 172.16.3.254

 10 network range 172.16.5.1 172.16.5.254

 20 network range 172.16.10.1 172.16.10.254

 30 network range 172.16.6.1 172.16.6.254

#

object-group ip address ⚌⚌⚌ż⚌⚌⚌1000M-⚌û⚌⚌⚌⚌⚌

 0 network range 172.16.100.1 172.16.100.254

 10 network range 172.16.1.1 172.16.1.254

 20 network range 172.16.4.1 172.16.4.254

#

object-group ip address ⚌ͨר⚌⚌-⚌û⚌⚌⚌⚌⚌

 0 network range 172.16.3.2 172.16.3.254

 10 network range 172.16.4.2 172.16.4.254

 20 network range 172.16.6.2 172.16.6.254

#

object-group service test2

 0 service tcp destination eq 443

 10 service tcp destination eq 80

#

ddns policy GigabitEthernet0/2

 url oray://***.***

 username hclhddns-cn

 password cipher $c$3$O1VzXfcK2GJtcUmNLCbYPmg8vxHiBKXhEKijakFN654=

#

policy-based-route aaa permit node 80

 if-match acl 3003

#

policy-based-route aaa permit node 90

 if-match acl 3009

#

policy-based-route aaa permit node 100

 if-match acl 3000

 apply output-interface Dialer0

#

policy-based-route aaa permit node 200

 if-match acl 3001

 apply output-interface Dialer1

#

policy-based-route aaa permit node 300

#

controller Cellular0/0

#

interface Dialer0

 bandwidth 1000000

 ppp chap password cipher $c$3$eQsFaclWLXYxDWVAPBV9ghXJ/Jgg6kxMXQ==

 ppp chap user 270116357069

 ppp ipcp dns admit-any

 ppp ipcp dns request

 ppp pap local-user 270116357069 password cipher $c$3$C0VuDt0PnDgIa4eqFVYAbtTgoJYVgY4MGg==

 dialer bundle enable

 dialer-group 1

 dialer timer idle 0

 dialer timer autodial 5

 dialer number 123 autodial

 ip address ppp-negotiate

 tcp mss 1280

 ip last-hop hold

 qos car inbound carl 6 cir 100000 cbs 6250000 ebs 0 green pass red discard yellow pass

 qos car outbound carl 5 cir 20000 cbs 1250000 ebs 0 green pass red discard yellow pass

 nat outbound

#

interface Dialer1

 bandwidth 1000000

 ppp chap password cipher $c$3$yO88Ms+onAVsFrK/g0mFjYsn0gF5gLU6Qw==

 ppp chap user 270116363484

 ppp ipcp dns admit-any

 ppp ipcp dns request

 ppp pap local-user 270116363484 password cipher $c$3$5X7BAYNENOaaa2Y1GTHrEuP6GIloydzr1w==

 dialer bundle enable

 dialer-group 3

 dialer timer idle 0

 dialer timer autodial 5

 ip address ppp-negotiate

 tcp mss 1280

 ip last-hop hold

 qos car inbound carl 4 cir 100000 cbs 6250000 ebs 0 green pass red discard yellow pass

 qos car outbound carl 3 cir 20000 cbs 1250000 ebs 0 green pass red discard yellow pass

 nat outbound

 nat server protocol tcp global current-interface 1433 inside 172.16.10.52 1433

 nat server protocol tcp global current-interface 8087 inside 172.16.10.201 8087

 nat server protocol tcp global current-interface 8088 inside 172.16.10.142 80

 nat server protocol tcp global current-interface 9000 inside 172.16.10.52 9000

 nat server protocol tcp global current-interface 9211 inside 172.16.10.201 9211

 nat server protocol tcp global current-interface 9500 inside 172.16.10.253 9500

 nat server protocol tcp global current-interface 9800 inside 172.16.10.245 9800

 nat server protocol tcp global current-interface 10000 inside 172.16.10.245 10000

 nat server protocol tcp global current-interface 10005 inside 172.16.10.245 10005

 nat server protocol tcp global current-interface 10086 inside 172.16.10.245 10086

 nat server protocol tcp global current-interface 10098 inside 172.16.10.245 10098

 nat server protocol tcp global current-interface 10271 inside 172.16.10.52 10271

 nat server protocol tcp global current-interface 11000 inside 172.16.10.245 11000

 nat server protocol tcp global current-interface 11434 inside 172.16.10.142 11434

 nat server protocol tcp global current-interface 12001 inside 172.16.10.253 22001

 nat server protocol tcp global current-interface 13001 inside 172.16.6.75 13001

 nat server protocol tcp global current-interface 14896 inside 172.16.10.254 14896

 nat server protocol tcp global current-interface 18000 inside 172.16.10.242 18000

 nat server protocol tcp global current-interface 62001 inside 172.16.10.253 62001

 nat hairpin enable

 ddns apply policy GigabitEthernet0/2 fqdn " ***.***"

 ipsec apply policy 1

#

interface Virtual-Template0

#

interface Virtual-Template1

 ppp authentication-mode chap

 remote address pool l2tp1

 ip address 172.16.110.1 255.255.255.0

 tcp mss 1280

#

interface NULL0

#

interface GigabitEthernet0/0

 port link-mode route

 ip address 192.168.8.1 255.255.255.0

 nat hairpin enable

 undo dhcp select server

 ip policy-based-route aaa

#

interface GigabitEthernet0/1

 port link-mode route

 description Multiple_Line

 dns server 202.103.24.68

 dns server 223.5.5.5

 tcp mss 1280

 ip last-hop hold

 nat server protocol tcp global current-interface 8180 inside 172.16.10.92 8180

 nat server protocol tcp global current-interface 8280 inside 172.16.10.92 8280

 nat server protocol tcp global current-interface 20081 inside 172.16.10.92 20081

 nat server protocol tcp global current-interface 20083 inside 172.16.10.92 20083

 nat server protocol tcp global current-interface 20184 inside 172.16.10.92 20184

 pppoe-client dial-bundle-number 0

#

interface GigabitEthernet0/2

 port link-mode route

 description Multiple_Line

 combo enable copper

 dns server 202.103.24.68

 dns server 223.5.5.5

 tcp mss 1280

 ip last-hop hold

 pppoe-client dial-bundle-number 1

#

interface GigabitEthernet0/3

 port link-mode route

 description Multiple_Line

 bandwidth 100000

 combo enable copper

 ip address 113.57.150.176 255.255.255.128

 dns server 218.104.111.114

 dns server 223.5.5.5

 tcp mss 1280

 ip last-hop hold

 qos car inbound carl 2 cir 10000 cbs 625000 ebs 0 green pass red discard yellow pass

 qos car outbound carl 1 cir 10000 cbs 625000 ebs 0 green pass red discard yellow pass

 nat outbound

 nat server protocol tcp global current-interface 1433 inside 172.16.10.52 1433

 nat server protocol tcp global current-interface 8087 inside 172.16.10.201 8087

 nat server protocol tcp global current-interface 8088 inside 172.16.10.142 80

 nat server protocol tcp global current-interface 9211 inside 172.16.10.201 9211

 nat server protocol tcp global current-interface 9500 inside 172.16.10.253 9500

 nat server protocol tcp global current-interface 9800 inside 172.16.10.245 9800

 nat server protocol tcp global current-interface 10000 inside 172.16.10.245 10000

 nat server protocol tcp global current-interface 10005 inside 172.16.10.245 10005

 nat server protocol tcp global current-interface 10086 inside 172.16.10.245 10086

 nat server protocol tcp global current-interface 10098 inside 172.16.10.245 10098

 nat server protocol tcp global current-interface 11000 inside 172.16.10.245 11000

 nat server protocol tcp global current-interface 11434 inside 172.16.10.142 11434

 nat server protocol tcp global current-interface 12001 inside 172.16.10.253 22001

 nat server protocol tcp global current-interface 13001 inside 172.16.6.75 13001

 nat server protocol tcp global current-interface 62001 inside 172.16.10.253 62001

 undo dhcp select server

#

interface GigabitEthernet0/4

 port link-mode route

#

interface GigabitEthernet0/5

 port link-mode route

#

interface SSLVPN-AC1

 ip address 172.16.160.254 255.255.255.0

#

object-policy ip Any-Any

 rule 0 pass

#

object-policy ip Trust-Any

 rule 0 pass

#

security-zone name Local

#

security-zone name Trust

 import interface GigabitEthernet0/0

#

security-zone name DMZ

#

security-zone name Untrust

 import interface Dialer0

 import interface Dialer1

 import interface GigabitEthernet0/1

 import interface GigabitEthernet0/2

 import interface GigabitEthernet0/3

 import interface SSLVPN-AC1

 import interface Virtual-Template1

#

security-zone name Management

#

zone-pair security source Any destination Any

 object-policy apply ip Any-Any

#

zone-pair security source Trust destination Any

 object-policy apply ip Trust-Any

#

 scheduler logfile size 16

#

line class console

 user-role network-admin

#

line class tty

 user-role network-operator

#

line class vty

 user-role network-operator

#

line con 0

 user-role network-admin

#

line vty 0 63

 authentication-mode scheme

 user-role network-operator

#

 ip route-static 0.0.0.0 0 Dialer0 preference 70

 ip route-static 0.0.0.0 0 GigabitEthernet0/3 113.57.150.129 preference 90

 ip route-static 0.0.0.0 0 192.168.1.1 preference 70 description to dianxin

 ip route-static 0.0.0.0 0 Dialer1

 ip route-static 172.16.1.0 24 192.168.8.2

 ip route-static 172.16.3.0 24 192.168.8.2

 ip route-static 172.16.4.0 24 192.168.8.2

 ip route-static 172.16.5.0 24 192.168.8.2

 ip route-static 172.16.6.0 24 192.168.8.2

 ip route-static 172.16.10.0 24 192.168.8.2

 ip route-static 172.16.100.0 23 192.168.8.2

#

 info-center loghost 127.0.0.1 port 3301

 info-center source CFGLOG loghost level informational

#

performance-management

#

 ssh server enable

 ssh server acl 3222

#

 time-range ⚌⚌⚌⚌ʱ⚌⚌ 09:00 to 12:00 working-day

 time-range ⚌⚌⚌⚌ʱ⚌⚌ 13:30 to 18:00 working-day

#

 ntp-service enable

 ntp-service unicast-server ***.***

 ntp-service unicast-server 203.107.6.88

#

acl advanced 3000

 rule 0 permit ip source 172.16.1.0 0.0.0.255

 rule 15 permit ip source 172.16.100.0 0.0.1.255

 rule 20 permit ip source 172.16.4.0 0.0.0.255

#

acl advanced 3001

 rule 10 permit ip source 172.16.5.0 0.0.0.255

 rule 15 permit ip source 172.16.10.0 0.0.0.255

 rule 20 permit ip source 172.16.3.0 0.0.0.255

 rule 25 permit ip source 172.16.6.0 0.0.0.255

#

acl advanced 3002

 rule 0 permit ip source 172.16.0.0 0.0.25.255 destination 172.16.0.0 0.0.255.255

#

acl advanced 3003

 rule 0 permit ip source 172.16.0.0 0.0.255.255 destination 172.16.0.0 0.0.255.255

 rule 5 permit ip source 172.16.0.0 0.0.255.255 destination 113.57.150.176 0

#

acl advanced 3005

 rule 0 permit ip

#

acl advanced 3008

#

acl advanced 3009

 rule 10 permit ip destination 172.16.10.245 0

#

acl advanced 3100

 rule 0 permit ip destination 113.57.150.176 0

#

acl advanced 3222

 rule 0 permit ip source 172.16.0.0 0.0.255.255 destination 192.168.8.1 0

#

acl advanced 3333

 rule 0 permit ip source 172.16.1.253 0 destination 113.57.150.176 0

 rule 5 permit ip source 172.16.1.253 0 destination 172.16.10.245 0

 rule 10 permit ip source 192.168.8.1 0 destination 172.16.10.245 0

 rule 15 permit ip source 172.16.10.245 0 destination 192.168.8.1 0

 rule 20 permit ip source 172.16.10.245 0 destination 172.16.1.253 0

 rule 25 permit ip source 113.57.150.176 0 destination 172.16.1.253 0

#

acl advanced 3666

 rule 1 permit ip source 113.110.145.101 0

 rule 2 permit ip destination 113.110.145.101 0

 rule 3 permit ip source 221.12.4.143 0

 rule 4 permit ip destination 221.12.4.143 0

#

 password-control enable

 undo password-control aging enable

 undo password-control history enable

 password-control length 6

 password-control login-attempt 3 exceed lock-time 10

 password-control update-interval 0

 password-control login idle-time 0

#

domain system

#

 domain default enable system

#

role name level-0

 description Predefined level-0 role

#

role name level-1

 description Predefined level-1 role

#

role name level-2

 description Predefined level-2 role

#

role name level-3

 description Predefined level-3 role

#

role name level-4

 description Predefined level-4 role

#

role name level-5

 description Predefined level-5 role

#

role name level-6

 description Predefined level-6 role

#

role name level-7

 description Predefined level-7 role

#

role name level-8

 description Predefined level-8 role

#

role name level-9

 description Predefined level-9 role

#

role name level-10

 description Predefined level-10 role

#

role name level-11

 description Predefined level-11 role

#

role name level-12

 description Predefined level-12 role

#

role name level-13

 description Predefined level-13 role

#

role name level-14

 description Predefined level-14 role

#

user-group system

#

local-user admin class manage

 service-type ssh telnet http https

 authorization-attribute user-role network-admin

#

local-user h3c class manage

 authorization-attribute user-role network-operator

#

local-user HC_FTY class network

 password cipher $c$3$7MdFXe73xXpB2JNLtUHYnMg7hFEs97OyBJnC2P0=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

 description ⚌⚌⚌⚌

#

local-user HC_LD class network

 password cipher $c$3$ZUr5yhPgmNaC1spjc8/aerb0AnUJnNO4H33FDKs=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user HC_LP class network

 password cipher $c$3$z6jIiDZzEVUm4lyvsD0Q9U5oHKEYz72cXmUInAw=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user HC_MD class network

 password cipher $c$3$td8zeypScK82st656vT5+cAo/g/RNl+rXMtqAxY=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user HC_md class network

 password cipher $c$3$24guu1o2QNP5rdkLO2uQTKK3q9QfFB2O+URTeQ0=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user QY_BC class network

 password cipher $c$3$s3pBhO9oB5YY9LUCWC4GaB+8FF/ihkxXAEwlArg=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_AI class network

 password cipher $c$3$gt00amReR8kuaQQvuAwmrwvBUdDGsdfiw/hdZPA=

 access-limit 10

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_CRM class network

 password cipher $c$3$ztFpxR2aZIV8Cu2nnKk3gjCZbrOKxz2ed23j3CU=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_DC class network

 password cipher $c$3$sSdHHj1u0BHZn8z6IBtjKNK0p6xE5lxTSvrdEZs=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_EMR class network

 password cipher $c$3$PIk21C5J2w9lkjQymguXwUTSqMfyNGPVRdT1rgw=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_HW01 class network

 password cipher $c$3$ug/KyZDfC6+XOdjm4EisTEJJ/9A8juDXRHBG8dE=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_HW02 class network

 password cipher $c$3$g7NMDMODublegunwfqk+ttQP9TlzDFlE0GLvwlg=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_LAB class network

 password cipher $c$3$+89EowWbe2Ya1T7Yfb53zOuy8WOnHR3jTp4iQC8=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user RD_XX class network

 password cipher $c$3$WdtgmmGcfP0AAMY35fxNrohR898rE5kSXKNh++o=

 access-limit 2

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user hcssl class network

 password cipher $c$3$ay85fczWDOHSHFq92qzcjRTvJyeBdXwg8rNz

 service-type sslvpn

 authorization-attribute user-role network-operator

 authorization-attribute sslvpn-policy-group SSL

#

local-user kevin class network

 password cipher $c$3$JeMyaA2gErvwNmq7dZGj7cp247Lyhd4IXTrdaj8=

 access-limit 2

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user qy_RD class network

 password cipher $c$3$nStfedOClSQRIPTWhJMis9tuDyQttyY+74QfYTE=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user qy_video class network

 password cipher $c$3$j6W759PkRdwo94IvnY1nSXN7oEYCcucHjp0/oic=

 access-limit 20

 service-type ppp

 authorization-attribute user-role network-operator

#

local-user test class network

 password cipher $c$3$psmzSBb4arcPuHsrZr+mDNszmtCQ6/J098JS

 service-type sslvpn

 authorization-attribute user-role network-operator

 authorization-attribute sslvpn-policy-group SSL

#

local-user test66 class network

 password cipher $c$3$UmalQrFajRw5HhccpRwaqP3dZuGl2g==

 service-type ppp

 authorization-attribute user-role level-15

 authorization-attribute user-role network-operator

#

local-user user1 class network

 password cipher $c$3$GbUrPpEvNS4GFPySB/0eqgnV7i5NpMSoV86x0Q2DMnY=

 service-type sslvpn

 authorization-attribute user-role network-operator

 authorization-attribute sslvpn-policy-group SSL

#

 security-enhanced level 2

#

ipsec transform-set 1

 esp encryption-algorithm 3des-cbc

 esp authentication-algorithm md5

#

ipsec transform-set 2

 esp encryption-algorithm aes-cbc-256

 esp authentication-algorithm md5

#

ipsec transform-set 3

 esp encryption-algorithm 3des-cbc

 esp authentication-algorithm sha1

#

ipsec transform-set 4

 esp encryption-algorithm aes-cbc-192

 esp authentication-algorithm md5

#

ipsec transform-set 5

 esp encryption-algorithm 3des-cbc

 esp authentication-algorithm md5

#

ipsec transform-set 6

 esp encryption-algorithm aes-cbc-256

 esp authentication-algorithm md5

#

ipsec transform-set 7

 esp encryption-algorithm 3des-cbc

 esp authentication-algorithm md5

#

ipsec transform-set 8

 esp encryption-algorithm aes-cbc-256

 esp authentication-algorithm md5

#

ipsec transform-set 11

 encapsulation-mode transport

 esp encryption-algorithm 3des-cbc

 esp authentication-algorithm sha1

#

ipsec transform-set 12

 encapsulation-mode transport

 esp encryption-algorithm aes-cbc-256

 esp authentication-algorithm sha256

#

ipsec policy-template 1 1

 transform-set 1 2 3 4 11 12

 ike-profile 1

#

ipsec policy 1 1 isakmp template 1

#

l2tp-group 1 mode lns

 allow l2tp virtual-template 1

 undo tunnel authentication

 tunnel name ins

 tunnel password cipher $c$3$jy4PvQozRaqM9VXA448+88hXU6aqWA==

#

 l2tp enable

#

ike profile 1

 keychain 1

 exchange-mode aggressive

 local-identity fqdn 123

 match remote identity fqdn 123

 proposal 1 2 3 4 5 6

#

ike proposal 1

#

ike proposal 2

 encryption-algorithm 3des-cbc

 dh group2

 authentication-algorithm md5

#

ike proposal 3

 encryption-algorithm 3des-cbc

 dh group2

 authentication-algorithm md5

#

ike proposal 4

 encryption-algorithm aes-cbc-256

 dh group2

 authentication-algorithm md5

#

ike proposal 5

 encryption-algorithm 3des-cbc

 dh group2

#

ike proposal 6

 encryption-algorithm aes-cbc-192

 dh group2

#

ike proposal 7

 dh group2

#

ike proposal 8

 encryption-algorithm aes-cbc-192

 dh group2

#

ike keychain 1

 pre-shared-key address 0.0.0.0 0.0.0.0 key cipher $c$3$BhLzfrwS4gkvFxQmr4VLLQlGFP0aXg==

#

 ip http acl advanced 3222

 ip https acl advanced 3222

 ip http enable

 ip https enable

#

wlan ap-group default-group

 vlan 1

#

sslvpn ip address-pool 160 172.16.160.2 172.16.160.250

#

sslvpn gateway gw

 ip address 0.0.0.0 port 9000

 service enable

#

sslvpn context ctxl

#

sslvpn context test

 gateway gw

 ip-tunnel interface SSLVPN-AC1

 ip-tunnel address-pool 160 mask 255.255.255.0

 ip-tunnel dns-server primary 223.5.5.5

 ip-tunnel dns-server secondary 8.8.8.8

 ip-route-list neiwang

  include 172.16.0.0 255.255.0.0

  include 192.168.0.0 255.255.0.0

 policy-group SSL

  filter ip-tunnel acl 3005

  ip-tunnel access-route ip-route-list neiwang

  ip-tunnel address-pool 160 mask 255.255.255.0

 service enable

#

 cloud-management server domain oasis.h3c.com

2 个回答
粉丝:33人 关注:2人

# MSR3600 Mac L2TP VPN 无法连接问题分析

>
> 设备版本:V7.1.064 Release 6728P26
> 现状:L2TP‑LNS,Virtual‑Template1,地址池`172.16.110.0/24`,**关闭隧道认证`undo tunnel authentication`**;PPP 认证 CHAP;Windows 客户端一般正常,**Mac 系统自带 L2TP 客户端连不上**。

## 一、Mac 原生 L2TP 客户端核心坑点(重点)

Mac OS 自带 L2TP 客户端**强制要求 L2TP 隧道认证(tunnel authentication)**,你配置了 `undo tunnel authentication`,这是 Mac 连不上最主要原因。

>
> Windows 客户端可以关闭隧道认证;**Mac 原生 L2TP 不支持无隧道密码模式**,必须配置隧道密码。

```
l2tp-group 1 mode lns
allow l2tp virtual-template 1
# undo tunnel authentication // ❌ Mac不支持,必须删掉这条
tunnel name ins
tunnel password cipher xxxxx // ✅必须配置隧道密码
```

>
> 注意:**隧道密码 ≠ PPP 用户密码**。
>
>
> - 隧道密码:L2TP 隧道层(L2TP group 下)
> - PPP 密码:local‑user 的 ppp 密码(Virtual‑Template 下 chap 认证)

### Mac 客户端设置对应:

系统设置→网络→L2TP VPN:

- 服务器地址:MSR 公网 IP
- 账户:PPP 用户名(如 HC_FTY)
- 密码:PPP 用户密码
- **密钥:填写 l2tp‑group 的 tunnel password 隧道密码**(Mac 这里叫 “密钥”,就是隧道密码)

---

## 二、现有配置其它问题点

### 1、安全策略 / 安全域

```
security‑zone name Untrust
import interface Virtual‑Template1
```

>
> Virtual‑Template1 加入 Untrust 域;当前`zone‑pair security source Any destination Any`,object‑policy Any‑any rule 0 pass,**域策略放行,这部分没问题**。

### 2、NAT 问题

MSR 有多条外网出口:Dialer0、Dialer1、G0/3 公网口。
L2TP 使用 UDP 500、4500、1701。

>
> 注意:**L2TP 的报文必须从**公网入接口回来,不能 PBR 策略路由把 L2TP 的报文强制转发到别的出口。
> 你有 PBR 策略`policy‑based‑route aaa`,**PBR 会作用到 L2TP 的回复报文,容易导致 L2TP 会话建立失败**。

👉 建议:**PBR 策略增加排除 L2TP 报文,ACL 3000/3001 里排除 UDP 1701、500、4500**;
或者在 PBR 的节点最前面增加一条,**L2TP 报文不做策略路由,走正常路由表**。

>
> 现象:Mac 发起 L2TP,路由器收到包,但是回复包被 PBR 转发到别的外网,客户端收不到响应,直接连接超时。

### 3、Virtual‑Template1 配置

```
interface Virtual‑Template1
ppp authentication‑mode chap
remote address pool l2tp1
ip address 172.16.110.1 255.255.255.0
tcp mss 1280
```

✅ PPP CHAP 认证没问题;

>
> Mac 客户端配置:**勾选「发送 PPP 回声请求」,加密方式选择 CHAP**,不要用 MS‑CHAPv2(V7 MSR 默认不支持 MS‑CHAPv2)。

### 4、路由问题

L2TP 客户端拿到`172.16.110.x`地址,访问内网 172.16.x.x;
设备已有静态路由指向 192.168.8.2,**回程路由正常**;

>
> 检查:`display ip routing‑table 172.16.110.0`,确认路由存在。

### 5、IKE/IPsec 这里注意

>
> 你的 L2TP 是**L2TP over IPsec**,配置了 ike profile 1,pre‑shared‑key;
> Mac 客户端:IPsec 预共享密钥,填写 ike keychain 里面的预共享密钥。

>
> 梳理完整的 Mac 配置参数:

1. 服务器地址:MSR 公网 IP
2. 账户:PPP 本地用户名(HC_FTY 等)
3. 用户密码:该 local‑user 的 ppp 密码
4. **密钥(L2TP 隧道密码):l2tp‑group 1 tunnel password**
5. IPsec 共享密钥:ike keychain 1 的 pre‑shared‑key
6. 认证:CHAP;不要 MS‑CHAPv2

---

## 三、排障命令(MSR 上执行)

1. 打开调试,看 L2TP、PPP、IPsec 交互

```
debugging l2tp packet
debugging ppp all
debugging ike all
terminal debugging
terminal monitor
```

>
> 观察:Mac 发起连接,是否收到 L2TP 的报文,有没有隧道建立、PPP 协商。

2. 查看 L2TP 会话

```
display l2tp session
display l2tp tunnel
```

- 如果**tunnel 建立不起来**:大概率隧道密码不匹配,或者 Mac 没填隧道密钥;
- 如果 tunnel 建立成功,PPP 协商失败:CHAP 用户名密码错误,或者 Mac 使用 MS‑CHAPv2;
- 如果 tunnel 和 PPP 都建立,但是上不了内网:PBR 策略路由、回程路由问题。

## 四、修改配置建议(关键)

### 1、删除 undo tunnel authentication,配置隧道密码

```
l2tp-group 1 mode lns
allow l2tp virtual-template 1
# undo tunnel authentication // 删除这一行!Mac不支持无隧道认证
tunnel name ins
tunnel password cipher 你的隧道密码
```

### 2、PBR 策略路由规避 L2TP 报文(非常关键,多出口环境必做)

>
> 现有 PBR 会拦截 L2TP 回复报文,导致连接失败。
> 新建 ACL,匹配 L2TP/IPsec 的 UDP 端口,PBR 最前面加节点,不做策略路由:

```
acl advanced 3099
rule 0 permit udp any any eq 1701
rule 1 permit udp any any eq 500
rule 2 permit udp any any eq 4500

policy-based-route aaa permit node 10
if-match acl 3099
#不apply输出接口,即走正常路由表
```

### 3、Mac 客户端配置要点

1. 网络→新建 L2TP VPN
2. 服务器地址:路由器公网 IP
3. 账户:PPP 本地用户名
4. 密码:PPP 用户密码
5. **密钥:L2TP 隧道密码(l2tp‑group tunnel password)**
6. 高级设置:
- 勾选「发送 PPP 回声请求」
- PPP 认证:**CHAP**,不要 MS‑CHAPv2
- 勾选「通过 VPN 发送所有流量」(测试用,确认连通)
7. IPsec 设置:预共享密钥填写 ike keychain 的 pre‑shared‑key

## 五、常见故障现象对照

1. **Mac 提示:连接失败,无法建立 VPN 连接**

>
> 大概率:`undo tunnel authentication`,Mac 不支持无隧道认证,隧道建立失败。

2. **能建立隧道,PPP 认证失败**

>
> Mac 使用 MS‑CHAPv2,MSR V7 默认不支持;改为 CHAP;核对 local‑user 的 service‑type ppp。

3. **VPN 连上,但是无法访问内网**

>
> PBR 策略路由导致回程报文走错出口;或者内网回程路由缺失。

4. **Windows 可以正常,Mac 不行**

>
> 90% 是**隧道认证(tunnel authentication)关闭**导致。Windows 可以跳过隧道密码,Mac 原生客户端强制要求。

>
> 补充:如果 Mac 不想用原生客户端,可以用第三方 L2TP 客户端,不需要隧道密码,但企业环境建议使用原生。

暂无评论

粉丝:31人 关注:1人

根据你提供的配置文件,我发现了几个可能导致 Mac 笔记本通过 L2TP VPN 连接失败的关键问题。

🔍 核心问题定位

1. L2TP 服务缺少 IPSec 保护(最可能的原因)

macOS 自带的 L2TP 客户端强制要求使用 IPSec 加密(L2TP over IPSec),而你的配置中:

text
l2tp-group 1 mode lns allow l2tp virtual-template 1 undo tunnel authentication tunnel name ins tunnel password cipher ...

缺少 IPSec 与 L2TP 的绑定配置。标准的 L2TP over IPSec 需要在 l2tp-group 下启用 ipsec 相关配置,例如:

text
l2tp-group 1 mode lns allow l2tp virtual-template 1 undo tunnel authentication tunnel name ins tunnel password cipher ... # 缺少以下关键配置 ipsec enable ipsec transform-set 1 # 需定义加密套件

2. IPSec 配置过于复杂且未正确关联

你的配置中定义了多个 ipsec transform-set 和 ike proposal,并有一个 ipsec policy 1 关联到 Dialer1 接口(用于公网出口),但 L2TP 服务本身并未启用 IPSec

此外,ike profile 1 中使用了 exchange-mode aggressive 和 local-identity fqdn 123,这种配置通常用于 L2TP over IPSec 的 NAT 穿透场景,但需要正确关联到 L2TP 组。

3. 安全域问题

Virtual-Template1 被加入了 Untrust 安全域:

text
security-zone name Untrust import interface Virtual-Template1

如果开启了安全域策略(目前配置中有 security-policy disable,但 zone-pair 存在),可能需要检查域间策略是否允许从 Untrust 到 Local/Trust 的访问。


🔧 解决方案

方案一:配置标准 L2TP over IPSec(推荐)

在现有配置基础上,添加以下关键配置:

bash
# 1. 修改 l2tp-group,启用 IPSec l2tp-group 1 mode lns allow l2tp virtual-template 1 undo tunnel authentication tunnel name ins tunnel password cipher $c$3$jy4PvQozRaqM9VXA448+88hXU6aqWA== ipsec enable # 启用 IPSec 保护 ipsec transform-set L2TP-IPSEC # 绑定加密套件 # 2. 定义一个专门用于 L2TP 的 IPSec transform-set ipsec transform-set L2TP-IPSEC esp encryption-algorithm aes-cbc-256 esp authentication-algorithm sha1 # 3. 定义一个专门用于 L2TP 的 IKE profile ike profile L2TP keychain L2TP exchange-mode aggressive local-identity fqdn ***.*** match remote identity fqdn any # 4. 定义对应的预共享密钥 ike keychain L2TP pre-shared-key address 0.0.0.0 0.0.0.0 key cipher YourPreSharedKey # 5. 在 l2tp-group 中关联 IKE profile(部分版本需要) l2tp-group 1 mode lns ike-profile L2TP

方案二:调整 macOS 客户端设置(临时方案)

如果短期内无法修改路由器配置,可以尝试在 Mac 上调整:

  1. 系统偏好设置 → 网络,选择你的 L2TP VPN 连接。

  2. 点击 高级 → 选项,勾选 “通过 VPN 连接发送所有流量”

  3. 在 “认证设置” 中,确保 “共享密钥” 与路由器配置的预共享密钥一致。

  4. ⚠️ 重要:如果路由器未启用 IPSec,Mac 上必须取消勾选 “使用 IPSec” 选项。但 macOS 新版系统可能不再支持纯 L2TP,所以方案一是根本解决之道


📋 关键检查点

检查项当前状态要求
L2TP 服务启用✅ 已启用必须
L2TP over IPSec❌ 未启用必须
预共享密钥✅ 已配置(IKE keychain)必须与客户端一致
NAT 穿透(NAT-T)❌ 未显式配置macOS 客户端通常需要
安全域策略⚠️ 存在 zone-pair 但 security-policy disable建议明确放行
地址池✅ 已配置(172.16.110.2-254)必须

💡 建议操作步骤

  1. 备份当前配置copy running-config startup-config

  2. 按照方案一添加 L2TP over IPSec 配置

  3. 确认防火墙放行端口:UDP 500(IKE)、UDP 4500(NAT-T)、ESP 协议。

  4. 配置 Mac 客户端

    • 服务器地址:路由器公网 IP

    • 账户名称:使用 local-user HC_XXX 中定义的 PPP 用户名(如 HC_FTY

    • 密码:对应的密码

    • 共享密钥ike keychain 中定义的预共享密钥

  5. 测试连接,并查看路由器日志:

    bash
    display logbuffer | include L2TP display logbuffer | include IPSEC

暂无评论

编辑答案

你正在编辑答案

如果你要对问题或其他回答进行点评或询问,请使用评论功能。

分享扩散:

提出建议

    +

亲~登录后才可以操作哦!

确定

亲~检测到您登陆的账号未在http://hclhub.h3c.com进行注册

注册后可访问此模块

跳转hclhub

你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作

举报

×

侵犯我的权益 >
对根叔社区有害的内容 >
辱骂、歧视、挑衅等(不友善)

侵犯我的权益

×

泄露了我的隐私 >
侵犯了我企业的权益 >
抄袭了我的内容 >
诽谤我 >
辱骂、歧视、挑衅等(不友善)
骚扰我

泄露了我的隐私

×

您好,当您发现根叔知了上有泄漏您隐私的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您认为哪些内容泄露了您的隐私?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)

侵犯了我企业的权益

×

您好,当您发现根叔知了上有关于您企业的造谣与诽谤、商业侵权等内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到 pub.zhiliao@h3c.com 邮箱,我们会在审核后尽快给您答复。
  • 1. 您举报的内容是什么?(请在邮件中列出您举报的内容和链接地址)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
  • 3. 是哪家企业?(营业执照,单位登记证明等证件)
  • 4. 您与该企业的关系是?(您是企业法人或被授权人,需提供企业委托授权书)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

抄袭了我的内容

×

原文链接或出处

诽谤我

×

您好,当您发现根叔知了上有诽谤您的内容时,您可以向根叔知了进行举报。 请您把以下内容通过邮件发送到pub.zhiliao@h3c.com 邮箱,我们会尽快处理。
  • 1. 您举报的内容以及侵犯了您什么权益?(请在邮件中列出您举报的内容、链接地址,并给出简短的说明)
  • 2. 您是谁?(身份证明材料,可以是身份证或护照等证件)
我们认为知名企业应该坦然接受公众讨论,对于答案中不准确的部分,我们欢迎您以正式或非正式身份在根叔知了上进行澄清。

对根叔社区有害的内容

×

垃圾广告信息
色情、暴力、血腥等违反法律法规的内容
政治敏感
不规范转载 >
辱骂、歧视、挑衅等(不友善)
骚扰我
诱导投票

不规范转载

×

举报说明