Problem connecting with L2TP on MacOS

Hello, I'm trying to connect via L2TP from MacOS High Sierra and am not having any luck.

I created a username and password for L2TP, and I know that L2TP works in general on my laptop because I connect to a firewall at work using it.

The message I get is that the L2TP server is not responding.  In the console log I get the following:



default	05:47:28.691098 -0500	racoon	plogsetfile: about to add racoon log file: /var/log/racoon.log
default	05:47:28.695118 -0500	racoon	accepted connection on vpn control socket.
default	05:47:28.695184 -0500	racoon	received bind command on vpn control socket.
default	05:47:28.695896 -0500	racoon	New Phase 2
default	05:47:28.695930 -0500	racoon	state changed to: IKEv1 quick I start
default	05:47:28.696364 -0500	racoon	Connecting.
default	05:47:28.696500 -0500	racoon	IPsec-SA request for 108.61.122.121 queued due to no Phase 1 found.
default	05:47:28.696548 -0500	racoon	New Phase 1
default	05:47:28.696581 -0500	racoon	state changed to: IKEv1 ident I start
default	05:47:28.696619 -0500	racoon	initiate new phase 1 negotiation: 10.254.14.88[500]<=>108.61.122.121[500]
default	05:47:28.696637 -0500	racoon	begin Identity Protection mode.
default	05:47:28.696652 -0500	racoon	IPSec Phase 1 started (Initiated by me).
default	05:47:28.697722 -0500	racoon	Resend Phase 1 packet 3c17ed5793c37497:0000000000000000
default	05:47:28.697755 -0500	racoon	state changed to: IKEv1 ident I msg1 sent
default	05:47:28.697801 -0500	racoon	IKE Packet: transmit success. (Initiator, Main-Mode message 1).
default	05:47:28.697842 -0500	racoon	>>>>> phase change status = Phase 1 started by us
default	05:47:28.729515 -0500	racoon	seen nptype=1(sa)
default	05:47:28.729536 -0500	racoon	seen nptype=13(vid)
default	05:47:28.729553 -0500	racoon	seen nptype=13(vid)
default	05:47:28.729569 -0500	racoon	seen nptype=13(vid)
default	05:47:28.729670 -0500	racoon	received Vendor ID: draft-ietf-ipsra-isakmp-xauth-06.txt
default	05:47:28.729693 -0500	racoon	received Vendor ID: DPD
default	05:47:28.729711 -0500	racoon	received Vendor ID: RFC 3947
default	05:47:28.729795 -0500	racoon	Selected NAT-T version: RFC 3947
default	05:47:28.729847 -0500	racoon	seen nptype=2(prop)
default	05:47:28.730054 -0500	racoon	seen nptype=3(trns)
default	05:47:28.731681 -0500	racoon	state changed to: IKEv1 ident I msg2 rcvd
default	05:47:28.731754 -0500	racoon	>>>>> phase change status = Phase 1 started by peer
default	05:47:28.731834 -0500	racoon	IKE Packet: receive success. (Initiator, Main-Mode message 2).
default	05:47:28.753261 -0500	racoon	Hashing 108.61.122.121[500] with algo #4
default	05:47:28.753341 -0500	racoon	Hashing 10.254.14.88[500] with algo #4
default	05:47:28.753377 -0500	racoon	Adding remote and local NAT-D payloads.
default	05:47:28.753885 -0500	racoon	Resend Phase 1 packet 3c17ed5793c37497:a8d9860bf928de6d
default	05:47:28.753939 -0500	racoon	state changed to: IKEv1 ident I msg3 sent
default	05:47:28.753976 -0500	racoon	IKE Packet: transmit success. (Initiator, Main-Mode message 3).
default	05:47:28.796520 -0500	racoon	seen nptype=4(ke)
default	05:47:28.796537 -0500	racoon	seen nptype=10(nonce)
default	05:47:28.796552 -0500	racoon	seen nptype=20(nat-d)
default	05:47:28.796568 -0500	racoon	seen nptype=20(nat-d)
default	05:47:28.796605 -0500	racoon	Hashing 10.254.14.88[500] with algo #4
default	05:47:28.796689 -0500	racoon	NAT-D payload #0 doesn't match
default	05:47:28.796753 -0500	racoon	Hashing 108.61.122.121[500] with algo #4
default	05:47:28.796820 -0500	racoon	NAT-D payload #1 verified
default	05:47:28.796838 -0500	racoon	NAT detected: ME
default	05:47:28.796926 -0500	racoon	state changed to: IKEv1 ident I msg4 rcvd
default	05:47:28.796952 -0500	racoon	IKE Packet: receive success. (Initiator, Main-Mode message 4).
default	05:47:28.808923 -0500	racoon	added initial-contact payload.
default	05:47:28.809889 -0500	racoon	Resend Phase 1 packet 3c17ed5793c37497:a8d9860bf928de6d
default	05:47:28.810026 -0500	racoon	state changed to: IKEv1 ident I msg5 sent
default	05:47:28.810152 -0500	racoon	IKE Packet: transmit success. (Initiator, Main-Mode message 5).
default	05:47:28.840326 -0500	racoon	Remote address mismatched. db=108.61.122.121[4500], act=108.61.122.121[500]
default	05:47:28.840363 -0500	racoon	receive Information.
error	05:47:28.840843 -0500	racoon	ignore information because the message is too short
default	05:47:28.840873 -0500	racoon	IKE Packet: receive failed. (Information message).
default	05:47:29.696562 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:30.696952 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:31.793304 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:32.110471 -0500	racoon	IKE Packet: transmit success. (Phase 1 Retransmit).
default	05:47:32.110521 -0500	racoon	Resend Phase 1 packet 3c17ed5793c37497:a8d9860bf928de6d
default	05:47:32.141836 -0500	racoon	Remote address mismatched. db=108.61.122.121[4500], act=108.61.122.121[500]
default	05:47:32.141872 -0500	racoon	receive Information.
error	05:47:32.142729 -0500	racoon	ignore information because the message is too short
default	05:47:32.142783 -0500	racoon	IKE Packet: receive failed. (Information message).
default	05:47:32.887164 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:33.970284 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:35.053439 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:35.288659 -0500	racoon	IKE Packet: transmit success. (Phase 1 Retransmit).
default	05:47:35.288762 -0500	racoon	Resend Phase 1 packet 3c17ed5793c37497:a8d9860bf928de6d
default	05:47:35.320729 -0500	racoon	Remote address mismatched. db=108.61.122.121[4500], act=108.61.122.121[500]
default	05:47:35.320773 -0500	racoon	receive Information.
error	05:47:35.322399 -0500	racoon	ignore information because the message is too short
default	05:47:35.322539 -0500	racoon	IKE Packet: receive failed. (Information message).
default	05:47:36.053662 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:37.053882 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:38.142769 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:38.587620 -0500	racoon	IKE Packet: transmit success. (Phase 1 Retransmit).
default	05:47:38.587691 -0500	racoon	Resend Phase 1 packet 3c17ed5793c37497:a8d9860bf928de6d
default	05:47:38.619271 -0500	racoon	Remote address mismatched. db=108.61.122.121[4500], act=108.61.122.121[500]
default	05:47:38.619291 -0500	racoon	receive Information.
error	05:47:38.619990 -0500	racoon	ignore information because the message is too short
default	05:47:38.620063 -0500	racoon	IKE Packet: receive failed. (Information message).
default	05:47:39.239822 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:40.335798 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:41.407758 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:42.487002 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:43.536967 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:44.635751 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:45.726986 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:46.807757 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:47.886885 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:48.936716 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:50.035658 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:50.588149 -0500	racoon	IKE Packet: transmit success. (Phase 1 Retransmit).
default	05:47:50.588191 -0500	racoon	Resend Phase 1 packet 3c17ed5793c37497:a8d9860bf928de6d
default	05:47:50.620329 -0500	racoon	Remote address mismatched. db=108.61.122.121[4500], act=108.61.122.121[500]
default	05:47:50.620362 -0500	racoon	receive Information.
error	05:47:50.621379 -0500	racoon	ignore information because the message is too short
default	05:47:50.621496 -0500	racoon	IKE Packet: receive failed. (Information message).
default	05:47:51.130710 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:52.225944 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:53.286697 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:54.286907 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:55.287082 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:56.386207 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:57.459820 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:58.460021 -0500	racoon	CHKPH1THERE: no established ph1 handler found
default	05:47:58.741972 -0500	racoon	vpn_control socket closed by peer.
default	05:47:58.742004 -0500	racoon	received disconnect all command.
default	05:47:58.742029 -0500	racoon	IPSec disconnecting from server 108.61.122.121
default	05:47:58.742047 -0500	racoon	in ike_session_purgephXbydstaddrwop... purging Phase 2 structures
default	05:47:58.742068 -0500	racoon	Phase 2 sa expired 10.254.14.88-108.61.122.121
default	05:47:58.742085 -0500	racoon	state changed to: Phase 2 expired
default	05:47:58.742126 -0500	racoon	in ike_session_purgephXbydstaddrwop... purging Phase 1 and related Phase 2 structures
default	05:47:58.742170 -0500	racoon	IPsec-SA needs to be purged: ESP 10.254.14.88[4500]->108.61.122.121[4500] spi=1342177280(0x50000000)
default	05:47:58.742208 -0500	racoon	ISAKMP-SA expired 10.254.14.88[4500]-108.61.122.121[4500] spi:3c17ed5793c37497:a8d9860bf928de6d
default	05:47:58.742235 -0500	racoon	state changed to: Phase 1 expired
default	05:47:58.742261 -0500	racoon	no ph1bind replacement found. NULL ph1.
default	05:47:58.742305 -0500	racoon	vpncontrol_close_comm.
... any ideas?

Comments

  • @swannie, if possible I would like to request that you submit a ticket to tech support with screenshots of your L2TP setup, or you can post here(I would just recommend blacking out anything personal) so that we may make sure you have configured the connection properly.
Sign In or Register to comment.