The Best L2TP Windows VPN setup for 2016 and 2019- Client, Server and FW instructions

Поделиться
HTML-код
  • Опубликовано: 19 авг 2024
  • НаукаНаука

Комментарии • 115

  • @user-wl7uf7qk9r
    @user-wl7uf7qk9r 3 года назад +1

    It is such a pleasure to listen to you. I can do it for hours. Internet finally paid back by ability to listen to your lectures. Thank you great professor!

    • @techpub
      @techpub  3 года назад

      Wow, thank you

  • @bicivelo
    @bicivelo 3 года назад +1

    Just tried this again on a 2019 server and it worked like a charm! I really appreciated the little details like the arp and netstat commands. Very useful. Thanks again!!

    • @techpub
      @techpub  3 года назад +1

      You're welcome!

  • @adilaljawahiri9616
    @adilaljawahiri9616 3 года назад

    Thanks! This worked. I've got DDNS set up on my Unifi UDM Pro, so I just used the hostname. (As I don't have a static public IP). Then port forwarded 1701, 4500 and 500 on the Port Forwarding section on Unifi. Your guide was great help! Only other thing I done was create another network policy and added a security group, so that only users in that group have VPN access.

  • @thomascarroll1916
    @thomascarroll1916 3 года назад +2

    On your previous L2TP video for Windows 2012, the registry entry on the server was AssumeUDPEncapsulationContextOnSendRule. In this video you have AssumeUDPEncapsulationOnSendRule for the server. Later on when creating the registry entry on the client, you use AssumeUDPEncapsulationContextOnSendRule. I’m pretty sure they should all be AssumeUDPEncapsulationContextOnSendRule.

    • @techpub
      @techpub  3 года назад

      The way I used them in each video worked so I wouldn't change anything.

    • @sirmixcomps
      @sirmixcomps 5 месяцев назад

      Does it work without Context?

  • @supremerulah420
    @supremerulah420 4 года назад

    Thanks Rob. I haven't received a notification in a while. I was delighted to get this one.

    • @techpub
      @techpub  4 года назад

      Thanks for watching.

  • @bicivelo
    @bicivelo 3 года назад

    the 2012 video was awesome! I used it for server 2016 and it worked as well. THANKS!!!

    • @techpub
      @techpub  3 года назад

      Great to hear!

    • @techpub
      @techpub  3 года назад

      Great to hear!

  • @winshawkhong9247
    @winshawkhong9247 3 месяца назад

    Installed the 2012R2 installation recently. The L2TP VPN server worked perfectly!. Then, proceeded to install the Server 2016 and followed all the steps as shown. On the part where we checked for open ports via Netstat, only UDP Port 500 and 4500 was listed. Strange, UDP Port 1701 was missing. To get the server to work, I manually opened UDP Port 1701 via the Windows Firewall.

    • @techpub
      @techpub  3 месяца назад

      Good troubleshooting. Thanks for watching!

  • @BritTheElder
    @BritTheElder 3 года назад +1

    Really glad I found your videos on this subject. Works perfectly on a Windows 10 pc. One question, will it work for a mac?

    • @techpub
      @techpub  3 года назад +1

      Yes it will also work on Android and iPhone.

  • @mwashington87
    @mwashington87 3 года назад

    Its great, thank you! I Always config pptp or sstp, pptp its NOT secure but is pratical and sstp os secure and more complicated, then now i will try l2tp (between pptp and sstp)

    • @techpub
      @techpub  3 года назад

      Glad it helped!

  • @Hubukai
    @Hubukai 3 года назад

    Very clear tutorial. Thanks for the time you put into it

    • @techpub
      @techpub  3 года назад

      Glad it was helpful!

  • @gojeda
    @gojeda 2 года назад

    Good video, thank you for that. Unfortunately I couldn't get it going, and I believe the issue is with Xfinity penchant for breaking VPNs. I tried, remotely, PPTP and L2TP. Neither connects.
    I have Server 2016 sitting behind a Xfinity box. My workstation, on the LAN locally to Server 2016, can connect to it just fine. Remotely, from my laptop (Win 10), it does not connect - telling me, "A connection to the remote computer could not be established. You might need to change the network settings for this connection."
    For giggles, I momentarily placed Server 2016 in the DMZ, and my remote laptop still could not connect to it. It gives me the same error above.
    When get back home, i will test the laptop on the LAN to see if it fails. My only options at this point, it seems, is to put the Xfinity box into bridge mode and buy my own router or switch to something like AT&T fiber.
    Any other pointers professor?

    • @techpub
      @techpub  2 года назад

      Thanks for watching. Yes Comcast home will block this in some locations. You can call them and ask them to remove the filter. Sometimes that works.

  • @estebangimenezgobello9992
    @estebangimenezgobello9992 4 года назад

    Thanks a lot Robert!! =) you really help me

    • @techpub
      @techpub  4 года назад

      Happy to help!

  • @lionelmasoane391
    @lionelmasoane391 2 года назад

    Brilliant video thank you.

    • @techpub
      @techpub  2 года назад

      Glad it was helpful!

  • @naveeshgupta
    @naveeshgupta 2 года назад

    Hi, i got connected with in the network but not outside the network, it is giving me this error "the L2TP connection attempt failed because processing error during initial negotiation with the remote computer". please help.

    • @techpub
      @techpub  2 года назад

      Definitely a firewall issue on your border firewall. You may need to contact the vendor to ensure the ports are properly opened, or use Wireshark to confirm.

  • @md.raishulislam8870
    @md.raishulislam8870 3 года назад

    Thanks a lot Bob, By the way, Others, Create a text file saving .reg after adding following EXACTLY to that file and execute that file double clicking on it:
    Windows Registry Editor Version 5.00
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\PolicyAgent]
    "AssumeUDPEncapsulationContextOnSendRule"=hex(b):02,00,00,00,00,00,00,00

    • @techpub
      @techpub  3 года назад

      Great tip. I will check it out.

  • @logicawe
    @logicawe 4 года назад

    Great content 👍, thanks for sharing.

    • @techpub
      @techpub  4 года назад +1

      Thanks for watching!

  • @YG-cr6el
    @YG-cr6el 3 года назад

    great tutorial. though, i couldn't figure out how to find nat ip address without cosco asa (don't have that one)...

    • @techpub
      @techpub  3 года назад

      Find out the model and you should be able to find a tutorial on that in YT or from the vendor. Thanks for watching.

  • @kostaschatzoudis7728
    @kostaschatzoudis7728 3 года назад +1

    Thank you for the video.
    Everything works fine when I'm connecting using the internal IP address of the server.
    However when I try to connect with the external IP address I get the error:
    "The L2TP connection attempt failed because the security layer encountered a processing error during initial negotiations with remote computer.".
    Does this mean I've screwed up the port forwarding?

    • @techpub
      @techpub  3 года назад +1

      CHeck out this article and look at the very bottom solution: community.sophos.com/xg-firewall/f/discussions/96945/vpn-l2tp-issue-with-windows-10#:~:text=The%20error%20message%3A%20%22The%20L2TP,fails%20for%20L2TP%2FIPSec%20connections.

    • @kostaschatzoudis7728
      @kostaschatzoudis7728 3 года назад

      @@techpub Thanks a lot. Turns out it was the router blocking the connection. I got a new router and everything seems to work.

  • @tashtsagouris7848
    @tashtsagouris7848 3 года назад

    Hello Sir, Thank you for this great video. I have set up a couple of servers using this video. I have one server that works with no issues using a Bell internet service provider. I have another that has a strange problem. After setting the server up, I can see the ports open, and I edit the registry on both the server and computers connecting to this server. I can VPN in on a local system. The issue is that when logging in from outside the network, I can easily log in with a service provider called Bell. Still, when trying with a different service provider Rogers/Cogeco, I get the error “ The L2TP connection attempt failed because the security layer encountered a processing error during the initial negotiation with the remote server. Or I get an error “ The network connection between your computer and the VPN server could not establish because the remote server is not responding. This could be because one of the network devices(e.g., Firewalls, NAT, routers, etc.) between your computer and the remote server is not configured to allow VPN connections.” Rogers and Cogeco use either an Arris modem/router or Hitron modem/router. I have troubled shoot many options with suggestions on the internet with no resolution. I am hoping maybe you or someone here can give a helping hand.

    • @tashtsagouris7848
      @tashtsagouris7848 3 года назад +1

      I was able to resolve this issue by changing the first registry entry that was mentioned in the video from AssumeUDPEncapsulationOnSendRule =2 to AssumeUDPEncapsulationContextOnSendRule =2. i had to add Context to the string.

    • @techpub
      @techpub  3 года назад

      Very good!

  • @user-ul7dn8tb4v
    @user-ul7dn8tb4v 3 года назад

    Thanks so much! But please, would it be possible to make a video on setting up an IKEv2 VPN server for Windows Server 2019?

    • @techpub
      @techpub  3 года назад

      Yes I will add it to the list.

  • @Martin-ot7xj
    @Martin-ot7xj Год назад

    Hi there, how to convert ip address to the hostname of the VPN server ??? for example i want to install a VPN server but i don't want to give the VPN server ip address to the clients i want to give them a dynamic hostname instead of ip address. how can I do that? ??thnx

    • @techpub
      @techpub  Год назад

      Thanks for watching. That won't be possible. They have to have an IP.

    • @Martin-ot7xj
      @Martin-ot7xj Год назад

      @@techpub hi ,it's possible. I a hostname Instead of IP on my Server, but i dont know the company convert hostname to IP address.for excample for sstp vpn we need a hostname Instead of IP.

  • @jaykellett7693
    @jaykellett7693 4 года назад

    invaluable! thank you so much!

    • @techpub
      @techpub  4 года назад

      You're very welcome!

  • @carlosrg68
    @carlosrg68 Год назад

    Thank you smart man, worked for me 👍

    • @techpub
      @techpub  Год назад

      You are welcome! Thanks for watching.

  • @rubengrigoryan8141
    @rubengrigoryan8141 3 года назад

    Thank you Robert. Very nice tutorial. I followed it and successfully built a VPN server. Only having ping/remote issues to the Win10. Can ping only to the AD and firewall. All other devices are not pingable. Any suggestions? Maybe VPN server is blocking ICMP?

    • @techpub
      @techpub  3 года назад

      Only the DC has ping opened up. Try this video to fix it: ruclips.net/video/2KigsB91w7s/видео.html

  • @MichaelP0418
    @MichaelP0418 2 года назад

    Great write up Robert. Worked like a charm. Just wondering do you have any info in relation to setting up RADIUS servers?

    • @techpub
      @techpub  2 года назад

      I do have a couple of radius videos on the channel, but they are wireless related. It should be the same procedure except you choose the other option instead of wifi when you launch NPS the first time. Thanks for watching!

    • @MichaelP0418
      @MichaelP0418 Год назад

      @@techpub that's cool thanks. One last question - do you have anything pertaining to a web application proxy, and how to implement that with the L2TP VPN server setup that you demonstrated in this video?

  • @sidewickx
    @sidewickx 3 года назад

    Within my network it's all good but when am outside trying to connect through my public IP am getting this error "the l2tp connection attempt failed because the security layer encountered a processing error during initial negotiations with the remote computer "

    • @techpub
      @techpub  3 года назад

      That is a firewall issue on the gateway. Run an NMap scan from the outside in and see which port is blocked.

    • @sidewickx
      @sidewickx 3 года назад

      @@techpub thanks for getting back at me. Let me run that will let you know.

    • @sidewickx
      @sidewickx 3 года назад

      @@techpub hey Rob. I ran an Nmap scan, the port that closed is port 113/tcp. This shouldn't give me a problem since this port should always be closed right... for its vulnerability to attacks. The thing is also that so weird is with Forticlient when am outside I can access my Router. The problem am having is connecting to my servers 🥲. This has been giving headaches for some months now

  • @ndwigz
    @ndwigz 3 года назад

    Hi Rob. Great video, I followed your steps and it worked fine. Now I want to change settings using server manager remotely. Can I access server manager as well?

    • @techpub
      @techpub  3 года назад +1

      You can do that by using remote desktop into a server or using Windows Admin Center. I have videos for both of these in my channel if you do a search.

    • @sidewickx
      @sidewickx 3 года назад

      @@techpub am trying to set up remote access on a vpn to connect to windows server at work from my home network, will this work for me but when i change to vpn install

  • @EddieRStevens
    @EddieRStevens 3 года назад

    Worked great! Thanks! Do you have a video, or can you recommend a resource, for setting this up using a certificate rather than a preshared key?

    • @techpub
      @techpub  3 года назад

      I don't have it but I do plan on making one.

    • @aurimuuuks
      @aurimuuuks 3 года назад

      @@techpub Maybe you managed to make some instructions to l2tp/ipsec with certificates?

  • @almoraz4301
    @almoraz4301 4 года назад

    @Robert McMillen great tutorial. How can i go about setting port forward to my internal address on a cisco router ?

    • @techpub
      @techpub  4 года назад

      It depends on the version you have and if you have the firewall package installed. Here's how to do it on an ASA Cisco firewall which would be similar. ruclips.net/video/ixoDGchuhG4/видео.html

    • @almoraz4301
      @almoraz4301 4 года назад

      @@techpub thanks for replaying. i opened the ports using a sophos firewall but only have communication on port 500 despite port forwarding on all 3 ports. when i check the server it shows all ports are there
      UDP 0.0.0.0:123 *:*
      UDP 0.0.0.0:389 *:*
      UDP 0.0.0.0:500 *:*
      UDP 0.0.0.0:1701 *:*
      UDP 0.0.0.0:3389 *:*
      UDP 0.0.0.0:3702 *:*
      UDP 0.0.0.0:3702 *:*
      UDP 0.0.0.0:4500 *:*

  • @lekinson5840
    @lekinson5840 3 года назад

    Great video! I only wish you made it for Certificates not PSK

    • @techpub
      @techpub  3 года назад +1

      I'll add it to the list.

    • @lekinson5840
      @lekinson5840 3 года назад

      @@techpub thanks! Still waiting for video because im stuck :(

  • @erfanziaee5904
    @erfanziaee5904 3 года назад

    Hello How are you today?
    I watched your instructions and it worked in the local network but i could not get connected from the outside...i have a mikrotik router and i opened the ports for l2tp to my server ip...but it did not work. Could you tell me the possible solutions?

    • @techpub
      @techpub  3 года назад

      I haven't used that type of firewall before. You may have to check out their support site.

  • @Tfm426
    @Tfm426 3 года назад

    i installed this on server 2019 when i run netstat 1701 does not show i tried running it 3 times always the same any ideas?

    • @techpub
      @techpub  3 года назад

      It should be TCP 1723 and not 1701.

  • @yassineboudhma5003
    @yassineboudhma5003 3 года назад

    do i have to open thos ports on home router ?

    • @techpub
      @techpub  3 года назад +1

      That's a tough one. Many home ISPs block these and you'll have to request they remove the block. Sometimes they won't.

  • @tmandrake1
    @tmandrake1 3 года назад

    Thanks Rob,
    My Internet uses NAT, how do I connect using L2TP with IPSEc?

    • @techpub
      @techpub  3 года назад

      This video shows using NAT as well so it should be the same or similar.

  • @israeljordan3437
    @israeljordan3437 4 года назад

    Hi Rob. Thanks a lot for your videos! I was able to connect from inside the network but not from outside. My environment has Server 2019 Essentials and Windows 10 clients. I followed all of your steps in this video. What should I do to troubleshoot?

    • @techpub
      @techpub  4 года назад

      If it works internally then it would be the firewall to your ISP that needs to be edited.

    • @israeljordan3437
      @israeljordan3437 4 года назад

      @@techpub I thought setting up port forwarding to the RAS ip address for port 500, 4500 and 1701 was what I needed to do. I have also opened all of those ports on the RAS windows firewall. I have also ran netstat -ab, netsh firewall show state and Neustadt-ano|findstr -i SYN_SENT to find not closed ports client side. Am I missing something?

    • @israeljordan3437
      @israeljordan3437 4 года назад

      @@techpub Update...I have double checked that port forwarding is enabled for udp ports 500, 1701 and 4500 on my router and in my anti-virus software. I have also made sure those ports are open in my RRAS.

    • @israeljordan3437
      @israeljordan3437 4 года назад

      @@techpub continued..I also used Wireshark on the RRAS and I can see traffic between host and client...what else do you suggest?

    • @israeljordan3437
      @israeljordan3437 4 года назад

      @@techpub The network connection between your computer and the server could not be established because the remote server is not responding.

  • @MrAc3zz
    @MrAc3zz 3 года назад

    Thank you for the video. I was able to connect locally via my client computer, however, when I attempt to connect externally it doesn't seem to work. I am using a comcast gateway, forwarding ports 1701, 500, and 4500 to the destination server. Any tips?

    • @techpub
      @techpub  3 года назад +1

      I believe you're running into the Comcast firewall. They block those ports. Sometimes you can get them to remove them but usually only the business clients get that.

    • @MrAc3zz
      @MrAc3zz 3 года назад +1

      @@techpub sir, you were right on the money. I put the Comcast modem into bridge mode and configured the port forwarding on a netgear nighthawk router. Works like a charm. Thanks again for the video.

  • @samuelmiller1691
    @samuelmiller1691 2 года назад

    Does this work for VPN connections coming from a non-domain joined PC?

    • @techpub
      @techpub  2 года назад

      Yes but you'll need an internal DNS server statically set on the VPN connection for you to resolve names.

    • @samuelmiller1691
      @samuelmiller1691 2 года назад

      @@techpub Thank you, I had to implement this last week for work. Internal DNS was the answer so thank you for this.

  • @antoniorodrigues8495
    @antoniorodrigues8495 3 года назад

    Hello Sir, I saw this video and its pretty cool to understand. I have Setup the VPN server using PPTP and it works perfect even when outside the Internal Lan. I'll now try to setup this L2TP VPN. I have doubt! Currently I added DHCP Relay Agent Protocol in Routing & remote Access Console and the properties are set with DHCP server's IP. Is this necessary ? and also i configured the VPN service using first option called (Remote Access {dial-up or VPN} ) that allowed me to choose network adapter for Wan Traffic, but in your case you have chosen Custom Configuration that did not prompted to choose the Network adapter for Outside communication. Please Suggest if i need to revert my settings and apply same settings as yours. Thanks.

    • @techpub
      @techpub  3 года назад +1

      I did that because my computer was behind a firewall. If your computer has 2 networks where one is directly on the internet then you did it correctly.

    • @antoniorodrigues8495
      @antoniorodrigues8495 3 года назад

      @@techpub Thank you Sir, i'll try setting it up.

  • @PhillipOReilly
    @PhillipOReilly 3 года назад

    Thanks for the video, quite helpful.
    You mentioned a NAT rule for return traffic, but I could not follow how to set that up exactly.
    The Windows server I set up with L2TP sits behind a Mikrotik router. The server's LAN side address is 192.10.0.100. I can access the VPN from the LAN side.
    It appears the client can contact the server but is getting no response. Any thoughts?
    Thanks.

    • @techpub
      @techpub  3 года назад +1

      I suggest using Zenmap from the outside to make sure all the expected UDP ports are responding. I'm thinking that something is missing there.

  • @jermaineguy589
    @jermaineguy589 3 года назад

    My network is set up like this. I have an isp router/modem which is connected to my cisco router and then to my cisco switch. my cisco router is the DHCP server for my local area network. On the cisco router, I have nat setup so my end devices are able to get internet. I followed your instruction am able to VPN locally but outside the network, I am not able to. I know you said to enable port forwarding on the isp modem but should I enable port forward for all the UDP ports, 1701, 500, 4500? or should I enable it on the cisco router? on my cisco router my access-list permits all so am not sure why it is not allowing it?

    • @ndwigz
      @ndwigz 3 года назад

      I have a similar set up. You still need to enable port forwarding on the Cisco router

    • @techpub
      @techpub  3 года назад

      Don't need to do it on the ISP modem, however if you use home ISP then it's likely the ISP is blocking it. I can only get it to work with business class internet.

    • @jermaineguy589
      @jermaineguy589 3 года назад

      @@techpub Thank you

  • @cristianmargarit3363
    @cristianmargarit3363 3 года назад

    Hello Robert,Thanks for the video, quite helpful. I tried to use the VPN from the outside, but it didn't work. The ports are open on my router. I notice small differences between REGYSTRY KEYS: "AssumeUDPEncapsulationContextOnSendRule" >> with and without "Context". There is ok ?

    • @techpub
      @techpub  2 года назад

      It's probably not the registry. I would check that the ports are actually open using nmap from the outside.

    • @cristianmargarit3363
      @cristianmargarit3363 2 года назад

      @@techpub Finally I manage to make it work, but on another machine(VM). The first one is an AD and is hosting some web sites,email server,etc. When the Remote works the web sites aren't accessible from outside. Most likely are some conflicts. Thank you for your message and for all material that you are posting on youtube.

  • @samirehman5907
    @samirehman5907 3 года назад

    can we do the same process on AD DS server ? and how do we create a member server ?

    • @techpub
      @techpub  3 года назад

      Yes you can put it on a domain controller if you want. A member server is just a Windows server you joined to the domain.

  • @micheledimauro1282
    @micheledimauro1282 3 года назад

    does the registry key is necessary? is hard to make that for all smart working users!

    • @techpub
      @techpub  3 года назад

      Only if using Windows devices for VPN.