mac 笔记本通过 l2tp 无法连接VPN
<msr3600>system-view
System View: return to User View with Ctrl+Z.
[msr3600]di
[msr3600]dis
[msr3600]display cu
[msr3600]display current-configuration
#
version 7.1.064, Release 6728P26
#
sysname msr3600
#
clock timezone beijing add 08:00:00
#
wlan global-configuration
#
telnet server enable
telnet server acl 3222
#
undo resource-monitor output syslog snmp-notification netconf-event
#
qos carl 1 source-ip-address object-group ⚌ͨר⚌⚌-⚌û⚌⚌⚌⚌⚌ per-address
qos carl 2 destination-ip-address object-group ⚌ͨר⚌⚌-⚌û⚌⚌⚌⚌⚌ per-address
qos carl 3 source-ip-address object-group ddns-⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌
qos carl 4 destination-ip-address object-group ddns-⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌
qos carl 5 source-ip-address object-group ⚌⚌⚌ż⚌⚌⚌1000M-⚌û⚌⚌⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌
qos carl 6 destination-ip-address object-group ⚌⚌⚌ż⚌⚌⚌1000M-⚌û⚌⚌⚌⚌⚌ per-address time-range ⚌⚌⚌⚌ʱ⚌⚌
#
security-zone intra-zone default permit
#
security-policy disable
#
track 1 nqa entry admin liantong reaction 1
#
ip pool l2tp1 172.16.110.2 172.16.110.254
#
dialer-group 1 rule ip permit
dialer-group 2 rule ip permit
dialer-group 3 rule ip permit
#
ip ttl-expires enable
#
ip load-sharing mode per-flow global
#
nat address-group 1
address 192.168.8.1 192.168.8.1
#
dns server 202.103.24.68
dns server 218.104.111.122
dns server 223.5.5.5
#
system-working-mode standard
password-recovery enable
#
vlan 1
#
object-group ip address ddns-⚌⚌⚌
0 network range 172.16.3.1 172.16.3.254
10 network range 172.16.5.1 172.16.5.254
20 network range 172.16.10.1 172.16.10.254
30 network range 172.16.6.1 172.16.6.254
#
object-group ip address ⚌⚌⚌ż⚌⚌⚌1000M-⚌û⚌⚌⚌⚌⚌
0 network range 172.16.100.1 172.16.100.254
10 network range 172.16.1.1 172.16.1.254
20 network range 172.16.4.1 172.16.4.254
#
object-group ip address ⚌ͨר⚌⚌-⚌û⚌⚌⚌⚌⚌
0 network range 172.16.3.2 172.16.3.254
10 network range 172.16.4.2 172.16.4.254
20 network range 172.16.6.2 172.16.6.254
#
object-group service test2
0 service tcp destination eq 443
10 service tcp destination eq 80
#
ddns policy GigabitEthernet0/2
url oray://***.***
username hclhddns-cn
password cipher $c$3$O1VzXfcK2GJtcUmNLCbYPmg8vxHiBKXhEKijakFN654=
#
policy-based-route aaa permit node 80
if-match acl 3003
#
policy-based-route aaa permit node 90
if-match acl 3009
#
policy-based-route aaa permit node 100
if-match acl 3000
apply output-interface Dialer0
#
policy-based-route aaa permit node 200
if-match acl 3001
apply output-interface Dialer1
#
policy-based-route aaa permit node 300
#
controller Cellular0/0
#
interface Dialer0
bandwidth 1000000
ppp chap password cipher $c$3$eQsFaclWLXYxDWVAPBV9ghXJ/Jgg6kxMXQ==
ppp chap user 270116357069
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user 270116357069 password cipher $c$3$C0VuDt0PnDgIa4eqFVYAbtTgoJYVgY4MGg==
dialer bundle enable
dialer-group 1
dialer timer idle 0
dialer timer autodial 5
dialer number 123 autodial
ip address ppp-negotiate
tcp mss 1280
ip last-hop hold
qos car inbound carl 6 cir 100000 cbs 6250000 ebs 0 green pass red discard yellow pass
qos car outbound carl 5 cir 20000 cbs 1250000 ebs 0 green pass red discard yellow pass
nat outbound
#
interface Dialer1
bandwidth 1000000
ppp chap password cipher $c$3$yO88Ms+onAVsFrK/g0mFjYsn0gF5gLU6Qw==
ppp chap user 270116363484
ppp ipcp dns admit-any
ppp ipcp dns request
ppp pap local-user 270116363484 password cipher $c$3$5X7BAYNENOaaa2Y1GTHrEuP6GIloydzr1w==
dialer bundle enable
dialer-group 3
dialer timer idle 0
dialer timer autodial 5
ip address ppp-negotiate
tcp mss 1280
ip last-hop hold
qos car inbound carl 4 cir 100000 cbs 6250000 ebs 0 green pass red discard yellow pass
qos car outbound carl 3 cir 20000 cbs 1250000 ebs 0 green pass red discard yellow pass
nat outbound
nat server protocol tcp global current-interface 1433 inside 172.16.10.52 1433
nat server protocol tcp global current-interface 8087 inside 172.16.10.201 8087
nat server protocol tcp global current-interface 8088 inside 172.16.10.142 80
nat server protocol tcp global current-interface 9000 inside 172.16.10.52 9000
nat server protocol tcp global current-interface 9211 inside 172.16.10.201 9211
nat server protocol tcp global current-interface 9500 inside 172.16.10.253 9500
nat server protocol tcp global current-interface 9800 inside 172.16.10.245 9800
nat server protocol tcp global current-interface 10000 inside 172.16.10.245 10000
nat server protocol tcp global current-interface 10005 inside 172.16.10.245 10005
nat server protocol tcp global current-interface 10086 inside 172.16.10.245 10086
nat server protocol tcp global current-interface 10098 inside 172.16.10.245 10098
nat server protocol tcp global current-interface 10271 inside 172.16.10.52 10271
nat server protocol tcp global current-interface 11000 inside 172.16.10.245 11000
nat server protocol tcp global current-interface 11434 inside 172.16.10.142 11434
nat server protocol tcp global current-interface 12001 inside 172.16.10.253 22001
nat server protocol tcp global current-interface 13001 inside 172.16.6.75 13001
nat server protocol tcp global current-interface 14896 inside 172.16.10.254 14896
nat server protocol tcp global current-interface 18000 inside 172.16.10.242 18000
nat server protocol tcp global current-interface 62001 inside 172.16.10.253 62001
nat hairpin enable
ddns apply policy GigabitEthernet0/2 fqdn " ***.***"
ipsec apply policy 1
#
interface Virtual-Template0
#
interface Virtual-Template1
ppp authentication-mode chap
remote address pool l2tp1
ip address 172.16.110.1 255.255.255.0
tcp mss 1280
#
interface NULL0
#
interface GigabitEthernet0/0
port link-mode route
ip address 192.168.8.1 255.255.255.0
nat hairpin enable
undo dhcp select server
ip policy-based-route aaa
#
interface GigabitEthernet0/1
port link-mode route
description Multiple_Line
dns server 202.103.24.68
dns server 223.5.5.5
tcp mss 1280
ip last-hop hold
nat server protocol tcp global current-interface 8180 inside 172.16.10.92 8180
nat server protocol tcp global current-interface 8280 inside 172.16.10.92 8280
nat server protocol tcp global current-interface 20081 inside 172.16.10.92 20081
nat server protocol tcp global current-interface 20083 inside 172.16.10.92 20083
nat server protocol tcp global current-interface 20184 inside 172.16.10.92 20184
pppoe-client dial-bundle-number 0
#
interface GigabitEthernet0/2
port link-mode route
description Multiple_Line
combo enable copper
dns server 202.103.24.68
dns server 223.5.5.5
tcp mss 1280
ip last-hop hold
pppoe-client dial-bundle-number 1
#
interface GigabitEthernet0/3
port link-mode route
description Multiple_Line
bandwidth 100000
combo enable copper
ip address 113.57.150.176 255.255.255.128
dns server 218.104.111.114
dns server 223.5.5.5
tcp mss 1280
ip last-hop hold
qos car inbound carl 2 cir 10000 cbs 625000 ebs 0 green pass red discard yellow pass
qos car outbound carl 1 cir 10000 cbs 625000 ebs 0 green pass red discard yellow pass
nat outbound
nat server protocol tcp global current-interface 1433 inside 172.16.10.52 1433
nat server protocol tcp global current-interface 8087 inside 172.16.10.201 8087
nat server protocol tcp global current-interface 8088 inside 172.16.10.142 80
nat server protocol tcp global current-interface 9211 inside 172.16.10.201 9211
nat server protocol tcp global current-interface 9500 inside 172.16.10.253 9500
nat server protocol tcp global current-interface 9800 inside 172.16.10.245 9800
nat server protocol tcp global current-interface 10000 inside 172.16.10.245 10000
nat server protocol tcp global current-interface 10005 inside 172.16.10.245 10005
nat server protocol tcp global current-interface 10086 inside 172.16.10.245 10086
nat server protocol tcp global current-interface 10098 inside 172.16.10.245 10098
nat server protocol tcp global current-interface 11000 inside 172.16.10.245 11000
nat server protocol tcp global current-interface 11434 inside 172.16.10.142 11434
nat server protocol tcp global current-interface 12001 inside 172.16.10.253 22001
nat server protocol tcp global current-interface 13001 inside 172.16.6.75 13001
nat server protocol tcp global current-interface 62001 inside 172.16.10.253 62001
undo dhcp select server
#
interface GigabitEthernet0/4
port link-mode route
#
interface GigabitEthernet0/5
port link-mode route
#
interface SSLVPN-AC1
ip address 172.16.160.254 255.255.255.0
#
object-policy ip Any-Any
rule 0 pass
#
object-policy ip Trust-Any
rule 0 pass
#
security-zone name Local
#
security-zone name Trust
import interface GigabitEthernet0/0
#
security-zone name DMZ
#
security-zone name Untrust
import interface Dialer0
import interface Dialer1
import interface GigabitEthernet0/1
import interface GigabitEthernet0/2
import interface GigabitEthernet0/3
import interface SSLVPN-AC1
import interface Virtual-Template1
#
security-zone name Management
#
zone-pair security source Any destination Any
object-policy apply ip Any-Any
#
zone-pair security source Trust destination Any
object-policy apply ip Trust-Any
#
scheduler logfile size 16
#
line class console
user-role network-admin
#
line class tty
user-role network-operator
#
line class vty
user-role network-operator
#
line con 0
user-role network-admin
#
line vty 0 63
authentication-mode scheme
user-role network-operator
#
ip route-static 0.0.0.0 0 Dialer0 preference 70
ip route-static 0.0.0.0 0 GigabitEthernet0/3 113.57.150.129 preference 90
ip route-static 0.0.0.0 0 192.168.1.1 preference 70 description to dianxin
ip route-static 0.0.0.0 0 Dialer1
ip route-static 172.16.1.0 24 192.168.8.2
ip route-static 172.16.3.0 24 192.168.8.2
ip route-static 172.16.4.0 24 192.168.8.2
ip route-static 172.16.5.0 24 192.168.8.2
ip route-static 172.16.6.0 24 192.168.8.2
ip route-static 172.16.10.0 24 192.168.8.2
ip route-static 172.16.100.0 23 192.168.8.2
#
info-center loghost 127.0.0.1 port 3301
info-center source CFGLOG loghost level informational
#
performance-management
#
ssh server enable
ssh server acl 3222
#
time-range ⚌⚌⚌⚌ʱ⚌⚌ 09:00 to 12:00 working-day
time-range ⚌⚌⚌⚌ʱ⚌⚌ 13:30 to 18:00 working-day
#
ntp-service enable
ntp-service unicast-server ***.***
ntp-service unicast-server 203.107.6.88
#
acl advanced 3000
rule 0 permit ip source 172.16.1.0 0.0.0.255
rule 15 permit ip source 172.16.100.0 0.0.1.255
rule 20 permit ip source 172.16.4.0 0.0.0.255
#
acl advanced 3001
rule 10 permit ip source 172.16.5.0 0.0.0.255
rule 15 permit ip source 172.16.10.0 0.0.0.255
rule 20 permit ip source 172.16.3.0 0.0.0.255
rule 25 permit ip source 172.16.6.0 0.0.0.255
#
acl advanced 3002
rule 0 permit ip source 172.16.0.0 0.0.25.255 destination 172.16.0.0 0.0.255.255
#
acl advanced 3003
rule 0 permit ip source 172.16.0.0 0.0.255.255 destination 172.16.0.0 0.0.255.255
rule 5 permit ip source 172.16.0.0 0.0.255.255 destination 113.57.150.176 0
#
acl advanced 3005
rule 0 permit ip
#
acl advanced 3008
#
acl advanced 3009
rule 10 permit ip destination 172.16.10.245 0
#
acl advanced 3100
rule 0 permit ip destination 113.57.150.176 0
#
acl advanced 3222
rule 0 permit ip source 172.16.0.0 0.0.255.255 destination 192.168.8.1 0
#
acl advanced 3333
rule 0 permit ip source 172.16.1.253 0 destination 113.57.150.176 0
rule 5 permit ip source 172.16.1.253 0 destination 172.16.10.245 0
rule 10 permit ip source 192.168.8.1 0 destination 172.16.10.245 0
rule 15 permit ip source 172.16.10.245 0 destination 192.168.8.1 0
rule 20 permit ip source 172.16.10.245 0 destination 172.16.1.253 0
rule 25 permit ip source 113.57.150.176 0 destination 172.16.1.253 0
#
acl advanced 3666
rule 1 permit ip source 113.110.145.101 0
rule 2 permit ip destination 113.110.145.101 0
rule 3 permit ip source 221.12.4.143 0
rule 4 permit ip destination 221.12.4.143 0
#
password-control enable
undo password-control aging enable
undo password-control history enable
password-control length 6
password-control login-attempt 3 exceed lock-time 10
password-control update-interval 0
password-control login idle-time 0
#
domain system
#
domain default enable system
#
role name level-0
description Predefined level-0 role
#
role name level-1
description Predefined level-1 role
#
role name level-2
description Predefined level-2 role
#
role name level-3
description Predefined level-3 role
#
role name level-4
description Predefined level-4 role
#
role name level-5
description Predefined level-5 role
#
role name level-6
description Predefined level-6 role
#
role name level-7
description Predefined level-7 role
#
role name level-8
description Predefined level-8 role
#
role name level-9
description Predefined level-9 role
#
role name level-10
description Predefined level-10 role
#
role name level-11
description Predefined level-11 role
#
role name level-12
description Predefined level-12 role
#
role name level-13
description Predefined level-13 role
#
role name level-14
description Predefined level-14 role
#
user-group system
#
local-user admin class manage
service-type ssh telnet http https
authorization-attribute user-role network-admin
#
local-user h3c class manage
authorization-attribute user-role network-operator
#
local-user HC_FTY class network
password cipher $c$3$7MdFXe73xXpB2JNLtUHYnMg7hFEs97OyBJnC2P0=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
description ⚌⚌⚌⚌
#
local-user HC_LD class network
password cipher $c$3$ZUr5yhPgmNaC1spjc8/aerb0AnUJnNO4H33FDKs=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user HC_LP class network
password cipher $c$3$z6jIiDZzEVUm4lyvsD0Q9U5oHKEYz72cXmUInAw=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user HC_MD class network
password cipher $c$3$td8zeypScK82st656vT5+cAo/g/RNl+rXMtqAxY=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user HC_md class network
password cipher $c$3$24guu1o2QNP5rdkLO2uQTKK3q9QfFB2O+URTeQ0=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user QY_BC class network
password cipher $c$3$s3pBhO9oB5YY9LUCWC4GaB+8FF/ihkxXAEwlArg=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_AI class network
password cipher $c$3$gt00amReR8kuaQQvuAwmrwvBUdDGsdfiw/hdZPA=
access-limit 10
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_CRM class network
password cipher $c$3$ztFpxR2aZIV8Cu2nnKk3gjCZbrOKxz2ed23j3CU=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_DC class network
password cipher $c$3$sSdHHj1u0BHZn8z6IBtjKNK0p6xE5lxTSvrdEZs=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_EMR class network
password cipher $c$3$PIk21C5J2w9lkjQymguXwUTSqMfyNGPVRdT1rgw=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_HW01 class network
password cipher $c$3$ug/KyZDfC6+XOdjm4EisTEJJ/9A8juDXRHBG8dE=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_HW02 class network
password cipher $c$3$g7NMDMODublegunwfqk+ttQP9TlzDFlE0GLvwlg=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_LAB class network
password cipher $c$3$+89EowWbe2Ya1T7Yfb53zOuy8WOnHR3jTp4iQC8=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user RD_XX class network
password cipher $c$3$WdtgmmGcfP0AAMY35fxNrohR898rE5kSXKNh++o=
access-limit 2
service-type ppp
authorization-attribute user-role network-operator
#
local-user hcssl class network
password cipher $c$3$ay85fczWDOHSHFq92qzcjRTvJyeBdXwg8rNz
service-type sslvpn
authorization-attribute user-role network-operator
authorization-attribute sslvpn-policy-group SSL
#
local-user kevin class network
password cipher $c$3$JeMyaA2gErvwNmq7dZGj7cp247Lyhd4IXTrdaj8=
access-limit 2
service-type ppp
authorization-attribute user-role network-operator
#
local-user qy_RD class network
password cipher $c$3$nStfedOClSQRIPTWhJMis9tuDyQttyY+74QfYTE=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user qy_video class network
password cipher $c$3$j6W759PkRdwo94IvnY1nSXN7oEYCcucHjp0/oic=
access-limit 20
service-type ppp
authorization-attribute user-role network-operator
#
local-user test class network
password cipher $c$3$psmzSBb4arcPuHsrZr+mDNszmtCQ6/J098JS
service-type sslvpn
authorization-attribute user-role network-operator
authorization-attribute sslvpn-policy-group SSL
#
local-user test66 class network
password cipher $c$3$UmalQrFajRw5HhccpRwaqP3dZuGl2g==
service-type ppp
authorization-attribute user-role level-15
authorization-attribute user-role network-operator
#
local-user user1 class network
password cipher $c$3$GbUrPpEvNS4GFPySB/0eqgnV7i5NpMSoV86x0Q2DMnY=
service-type sslvpn
authorization-attribute user-role network-operator
authorization-attribute sslvpn-policy-group SSL
#
security-enhanced level 2
#
ipsec transform-set 1
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5
#
ipsec transform-set 2
esp encryption-algorithm aes-cbc-256
esp authentication-algorithm md5
#
ipsec transform-set 3
esp encryption-algorithm 3des-cbc
esp authentication-algorithm sha1
#
ipsec transform-set 4
esp encryption-algorithm aes-cbc-192
esp authentication-algorithm md5
#
ipsec transform-set 5
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5
#
ipsec transform-set 6
esp encryption-algorithm aes-cbc-256
esp authentication-algorithm md5
#
ipsec transform-set 7
esp encryption-algorithm 3des-cbc
esp authentication-algorithm md5
#
ipsec transform-set 8
esp encryption-algorithm aes-cbc-256
esp authentication-algorithm md5
#
ipsec transform-set 11
encapsulation-mode transport
esp encryption-algorithm 3des-cbc
esp authentication-algorithm sha1
#
ipsec transform-set 12
encapsulation-mode transport
esp encryption-algorithm aes-cbc-256
esp authentication-algorithm sha256
#
ipsec policy-template 1 1
transform-set 1 2 3 4 11 12
ike-profile 1
#
ipsec policy 1 1 isakmp template 1
#
l2tp-group 1 mode lns
allow l2tp virtual-template 1
undo tunnel authentication
tunnel name ins
tunnel password cipher $c$3$jy4PvQozRaqM9VXA448+88hXU6aqWA==
#
l2tp enable
#
ike profile 1
keychain 1
exchange-mode aggressive
local-identity fqdn 123
match remote identity fqdn 123
proposal 1 2 3 4 5 6
#
ike proposal 1
#
ike proposal 2
encryption-algorithm 3des-cbc
dh group2
authentication-algorithm md5
#
ike proposal 3
encryption-algorithm 3des-cbc
dh group2
authentication-algorithm md5
#
ike proposal 4
encryption-algorithm aes-cbc-256
dh group2
authentication-algorithm md5
#
ike proposal 5
encryption-algorithm 3des-cbc
dh group2
#
ike proposal 6
encryption-algorithm aes-cbc-192
dh group2
#
ike proposal 7
dh group2
#
ike proposal 8
encryption-algorithm aes-cbc-192
dh group2
#
ike keychain 1
pre-shared-key address 0.0.0.0 0.0.0.0 key cipher $c$3$BhLzfrwS4gkvFxQmr4VLLQlGFP0aXg==
#
ip http acl advanced 3222
ip https acl advanced 3222
ip http enable
ip https enable
#
wlan ap-group default-group
vlan 1
#
sslvpn ip address-pool 160 172.16.160.2 172.16.160.250
#
sslvpn gateway gw
ip address 0.0.0.0 port 9000
service enable
#
sslvpn context ctxl
#
sslvpn context test
gateway gw
ip-tunnel interface SSLVPN-AC1
ip-tunnel address-pool 160 mask 255.255.255.0
ip-tunnel dns-server primary 223.5.5.5
ip-tunnel dns-server secondary 8.8.8.8
ip-route-list neiwang
include 172.16.0.0 255.255.0.0
include 192.168.0.0 255.255.0.0
policy-group SSL
filter ip-tunnel acl 3005
ip-tunnel access-route ip-route-list neiwang
ip-tunnel address-pool 160 mask 255.255.255.0
service enable
#
cloud-management server domain oasis.h3c.com
# MSR3600 Mac L2TP VPN 无法连接问题分析
>
> 设备版本:V7.1.064 Release 6728P26
> 现状:L2TP‑LNS,Virtual‑Template1,地址池`172.16.110.0/24`,**关闭隧道认证`undo tunnel authentication`**;PPP 认证 CHAP;Windows 客户端一般正常,**Mac 系统自带 L2TP 客户端连不上**。
## 一、Mac 原生 L2TP 客户端核心坑点(重点)
Mac OS 自带 L2TP 客户端**强制要求 L2TP 隧道认证(tunnel authentication)**,你配置了 `undo tunnel authentication`,这是 Mac 连不上最主要原因。
>
> Windows 客户端可以关闭隧道认证;**Mac 原生 L2TP 不支持无隧道密码模式**,必须配置隧道密码。
```
l2tp-group 1 mode lns
allow l2tp virtual-template 1
# undo tunnel authentication // ❌ Mac不支持,必须删掉这条
tunnel name ins
tunnel password cipher xxxxx // ✅必须配置隧道密码
```
>
> 注意:**隧道密码 ≠ PPP 用户密码**。
>
>
> - 隧道密码:L2TP 隧道层(L2TP group 下)
> - PPP 密码:local‑user 的 ppp 密码(Virtual‑Template 下 chap 认证)
### Mac 客户端设置对应:
系统设置→网络→L2TP VPN:
- 服务器地址:MSR 公网 IP
- 账户:PPP 用户名(如 HC_FTY)
- 密码:PPP 用户密码
- **密钥:填写 l2tp‑group 的 tunnel password 隧道密码**(Mac 这里叫 “密钥”,就是隧道密码)
---
## 二、现有配置其它问题点
### 1、安全策略 / 安全域
```
security‑zone name Untrust
import interface Virtual‑Template1
```
>
> Virtual‑Template1 加入 Untrust 域;当前`zone‑pair security source Any destination Any`,object‑policy Any‑any rule 0 pass,**域策略放行,这部分没问题**。
### 2、NAT 问题
MSR 有多条外网出口:Dialer0、Dialer1、G0/3 公网口。
L2TP 使用 UDP 500、4500、1701。
>
> 注意:**L2TP 的报文必须从**公网入接口回来,不能 PBR 策略路由把 L2TP 的报文强制转发到别的出口。
> 你有 PBR 策略`policy‑based‑route aaa`,**PBR 会作用到 L2TP 的回复报文,容易导致 L2TP 会话建立失败**。
👉 建议:**PBR 策略增加排除 L2TP 报文,ACL 3000/3001 里排除 UDP 1701、500、4500**;
或者在 PBR 的节点最前面增加一条,**L2TP 报文不做策略路由,走正常路由表**。
>
> 现象:Mac 发起 L2TP,路由器收到包,但是回复包被 PBR 转发到别的外网,客户端收不到响应,直接连接超时。
### 3、Virtual‑Template1 配置
```
interface Virtual‑Template1
ppp authentication‑mode chap
remote address pool l2tp1
ip address 172.16.110.1 255.255.255.0
tcp mss 1280
```
✅ PPP CHAP 认证没问题;
>
> Mac 客户端配置:**勾选「发送 PPP 回声请求」,加密方式选择 CHAP**,不要用 MS‑CHAPv2(V7 MSR 默认不支持 MS‑CHAPv2)。
### 4、路由问题
L2TP 客户端拿到`172.16.110.x`地址,访问内网 172.16.x.x;
设备已有静态路由指向 192.168.8.2,**回程路由正常**;
>
> 检查:`display ip routing‑table 172.16.110.0`,确认路由存在。
### 5、IKE/IPsec 这里注意
>
> 你的 L2TP 是**L2TP over IPsec**,配置了 ike profile 1,pre‑shared‑key;
> Mac 客户端:IPsec 预共享密钥,填写 ike keychain 里面的预共享密钥。
>
> 梳理完整的 Mac 配置参数:
1. 服务器地址:MSR 公网 IP
2. 账户:PPP 本地用户名(HC_FTY 等)
3. 用户密码:该 local‑user 的 ppp 密码
4. **密钥(L2TP 隧道密码):l2tp‑group 1 tunnel password**
5. IPsec 共享密钥:ike keychain 1 的 pre‑shared‑key
6. 认证:CHAP;不要 MS‑CHAPv2
---
## 三、排障命令(MSR 上执行)
1. 打开调试,看 L2TP、PPP、IPsec 交互
```
debugging l2tp packet
debugging ppp all
debugging ike all
terminal debugging
terminal monitor
```
>
> 观察:Mac 发起连接,是否收到 L2TP 的报文,有没有隧道建立、PPP 协商。
2. 查看 L2TP 会话
```
display l2tp session
display l2tp tunnel
```
- 如果**tunnel 建立不起来**:大概率隧道密码不匹配,或者 Mac 没填隧道密钥;
- 如果 tunnel 建立成功,PPP 协商失败:CHAP 用户名密码错误,或者 Mac 使用 MS‑CHAPv2;
- 如果 tunnel 和 PPP 都建立,但是上不了内网:PBR 策略路由、回程路由问题。
## 四、修改配置建议(关键)
### 1、删除 undo tunnel authentication,配置隧道密码
```
l2tp-group 1 mode lns
allow l2tp virtual-template 1
# undo tunnel authentication // 删除这一行!Mac不支持无隧道认证
tunnel name ins
tunnel password cipher 你的隧道密码
```
### 2、PBR 策略路由规避 L2TP 报文(非常关键,多出口环境必做)
>
> 现有 PBR 会拦截 L2TP 回复报文,导致连接失败。
> 新建 ACL,匹配 L2TP/IPsec 的 UDP 端口,PBR 最前面加节点,不做策略路由:
```
acl advanced 3099
rule 0 permit udp any any eq 1701
rule 1 permit udp any any eq 500
rule 2 permit udp any any eq 4500
policy-based-route aaa permit node 10
if-match acl 3099
#不apply输出接口,即走正常路由表
```
### 3、Mac 客户端配置要点
1. 网络→新建 L2TP VPN
2. 服务器地址:路由器公网 IP
3. 账户:PPP 本地用户名
4. 密码:PPP 用户密码
5. **密钥:L2TP 隧道密码(l2tp‑group tunnel password)**
6. 高级设置:
- 勾选「发送 PPP 回声请求」
- PPP 认证:**CHAP**,不要 MS‑CHAPv2
- 勾选「通过 VPN 发送所有流量」(测试用,确认连通)
7. IPsec 设置:预共享密钥填写 ike keychain 的 pre‑shared‑key
## 五、常见故障现象对照
1. **Mac 提示:连接失败,无法建立 VPN 连接**
>
> 大概率:`undo tunnel authentication`,Mac 不支持无隧道认证,隧道建立失败。
2. **能建立隧道,PPP 认证失败**
>
> Mac 使用 MS‑CHAPv2,MSR V7 默认不支持;改为 CHAP;核对 local‑user 的 service‑type ppp。
3. **VPN 连上,但是无法访问内网**
>
> PBR 策略路由导致回程报文走错出口;或者内网回程路由缺失。
4. **Windows 可以正常,Mac 不行**
>
> 90% 是**隧道认证(tunnel authentication)关闭**导致。Windows 可以跳过隧道密码,Mac 原生客户端强制要求。
>
> 补充:如果 Mac 不想用原生客户端,可以用第三方 L2TP 客户端,不需要隧道密码,但企业环境建议使用原生。
根据你提供的配置文件,我发现了几个可能导致 Mac 笔记本通过 L2TP VPN 连接失败的关键问题。
macOS 自带的 L2TP 客户端强制要求使用 IPSec 加密(L2TP over IPSec),而你的配置中:
缺少 IPSec 与 L2TP 的绑定配置。标准的 L2TP over IPSec 需要在 l2tp-group 下启用 ipsec 相关配置,例如:
你的配置中定义了多个 ipsec transform-set 和 ike proposal,并有一个 ipsec policy 1 关联到 Dialer1 接口(用于公网出口),但 L2TP 服务本身并未启用 IPSec。
此外,ike profile 1 中使用了 exchange-mode aggressive 和 local-identity fqdn 123,这种配置通常用于 L2TP over IPSec 的 NAT 穿透场景,但需要正确关联到 L2TP 组。
Virtual-Template1 被加入了 Untrust 安全域:
如果开启了安全域策略(目前配置中有 security-policy disable,但 zone-pair 存在),可能需要检查域间策略是否允许从 Untrust 到 Local/Trust 的访问。
在现有配置基础上,添加以下关键配置:
如果短期内无法修改路由器配置,可以尝试在 Mac 上调整:
系统偏好设置 → 网络,选择你的 L2TP VPN 连接。
点击 高级 → 选项,勾选 “通过 VPN 连接发送所有流量”。
在 “认证设置” 中,确保 “共享密钥” 与路由器配置的预共享密钥一致。
⚠️ 重要:如果路由器未启用 IPSec,Mac 上必须取消勾选 “使用 IPSec” 选项。但 macOS 新版系统可能不再支持纯 L2TP,所以方案一是根本解决之道。
| 检查项 | 当前状态 | 要求 |
|---|---|---|
| L2TP 服务启用 | ✅ 已启用 | 必须 |
| L2TP over IPSec | ❌ 未启用 | 必须 |
| 预共享密钥 | ✅ 已配置(IKE keychain) | 必须与客户端一致 |
| NAT 穿透(NAT-T) | ❌ 未显式配置 | macOS 客户端通常需要 |
| 安全域策略 | ⚠️ 存在 zone-pair 但 security-policy disable | 建议明确放行 |
| 地址池 | ✅ 已配置(172.16.110.2-254) | 必须 |
备份当前配置:copy running-config startup-config
按照方案一添加 L2TP over IPSec 配置。
确认防火墙放行端口:UDP 500(IKE)、UDP 4500(NAT-T)、ESP 协议。
配置 Mac 客户端:
服务器地址:路由器公网 IP
账户名称:使用 local-user HC_XXX 中定义的 PPP 用户名(如 HC_FTY)
密码:对应的密码
共享密钥:ike keychain 中定义的预共享密钥
测试连接,并查看路由器日志:
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论