This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Can somebody help me with analyzing my capture ipsec/l2tp

0

Hello community, I have setup a zywall firewall which gives me the possibility to connect via L2TP. Our customers connect to this, but we have only one where it is not working.

I have already connected via teamviewer to the customer and looked in his VPN settings. All ok.

Now I the only possibility is now that his router makes some troubles. Therefore I installed Wireshark on his computer and captured the "try" to establish a connection to our router. Following you will find the captured analyze.

Only what makes me really crazy is, that sometimes he can connect. But only sometimes. When I look on my firewall I see him trying to connect (see Port 500 coming in) - most of the time after Port 500 nothing more. But there should be still Port 1701 and 4500.

Information about the captured file: My firewall has the ip 61.50.148.122 His client ip address is 192.168.0.132 Okay hopefully somebody can find something in my log, I sadly don`t understand the logfile. For me there is nowhere a failure. But please see below: Click me for the catpure

Thank you Paul

asked 20 Aug '15, 01:26

Paul6552's gravatar image

Paul6552
6112
accept rate: 0%


One Answer:

0

Is only the client who runs Windows on Apple having problems?

ISAKMP phase 2 is not being established. Check the logs on the firewall. It will be easier than decrypting the packet capture.

answered 20 Aug '15, 06:24

Roland's gravatar image

Roland
7642415
accept rate: 13%

Hello Roland,

Here is the log from my firewall: alt text

I see only that the Client has send some information and then it is over. I think the Firewall is waiting for something, but when I look in the captured wireshark file on the client side I see that the client is sending all the time things to the firewall but they don`t arrive by the firewall.

(20 Aug '15, 17:26) Paul6552

The screenshot is not helping. Maybe you can turn on a vpn debug on the device.

(21 Aug '15, 11:30) Roland