L2TP IPSEC to Cisco ASA

Anyone have any luck getting a connection to a ASA sever via L2TP IPSEC ? If so, what IKE.IPSEC SA's did you create use. I looked at my racoon dynamic config and matched the phase 1 and 2, but no luck so far, getting the following error in my ASA log.

%ASA-7-713906: Group = xxxxxx_l2tp, IP = 1.1.1.1 All SA proposals found unacceptable
%ASA-7-713906: IP = 1.1.1.1, All IKE SA proposals found unacceptable!

Macbook Pro 2.16, Mac OS X (10.4.8)

Posted on Jul 2, 2007 1:24 PM

Reply
4 replies

Jul 4, 2007 8:53 PM in response to jeremyarcher

After 7 hours of working on this tonight I finally got it working. Ahh.. I have my new iPhone working with a Cisco ASA w/ L2TP.

The Cisco documentation is wrong. Instead of using a transport protocol with 3DES-MD5 use ESP-3DES-MD5.

For iPhone users:
Apple has its share of problems with the iPhone in this regard as well.

1) The VPN password does not save. You must enter it each time you try and bring up the VPN but the screen to enter the password only allows numeric characters. Therefore, make sure your remote access user account is numbers only.

2) Neither Split-tunneling nor the proxy setting in the VPN config works. I ran a packet capture on it and the iPhone never sends the request to the internal proxy server. Therefore, at least at this time, put aside all hopes of using the iPhone w/ VPN and being online at the same time. You'll have to bring up the VPN each time you want to sync mail or access internal web servers.

3) Finally, because of these limitations it seems better to me to enable the Email Proxy services on the ASA and tunnel inbound IMAPS and STMPS to the internal email servers. This eliminates the need for the VPN device (as long as you don't need web access to internal web servers).

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

L2TP IPSEC to Cisco ASA

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.