Ubiquiti UniFi L2TP IPsec VPN Failure and Fix

preview_player
Показать описание
Something old, something new. This something can make you Blue. A really old bug in UniFi that stops or breaks your L2TP IPSec User VPNs. Turn off the new interface and create your VPN, then enable the new interface.

00:00 - Intro
00:10 - What's the problem?
01:15 - What's the fix?
03:10 - Wrap Up

Affiliate Links:

Contact us for network consulting and best practices deployment today! We support all Grandstream, DrayTek, Obihai, Poly, Ubiquiti, MikroTik, Extreme, Palo Alto, and more!

Come back for the next video!
Twitter - @WillieHowe
Instagram - @howex5
TikTok - @whowe82

SUBSCRIBE! THUMBS-UP! Comment and Share!
Рекомендации по теме
Комментарии
Автор

@Willie, Its been almost a year and I rolled out a new Dream machine, is there still an issue with new interface?

genesorkin
Автор

Has the VPN bug been fixed where windows client sessions do not get closed properly and you have to restart VPN services before they can connect again?

DavidFaris
Автор

I’m trying to create a site but this new UniFi UI won’t let me is there something I’m missing?

rohanpatel
Автор

Have they disabled this feature on current update to UNIFI for USG? I have 7.x and I have never been able to get the l2tp vpn to work. I have it sitting behind my ONT so there is no other router in between this USG and the ONT. However, "ShieldsUp" always shows "passed" for all ports no matter what I do. Is my device possibly broken? (I.E. defaulted to drop packets coming in as "new" no matter what the UI says the firewall rules are doing?)

MartesWigglesworth
Автор

Hello Willie, I have had this problem for a while, before the new interface. I would intermittently have VPN fail but after a reboot it usually came back. I created the original L2TP VPN with the classic interface, before the new interface was available. And I've only recently switched to the new interface. I'll retry the "new" site re-build in the classic interface but I'm skeptical that this is the solution. I've seen other message boards with a solution to SSH into the system, disable the Radius Server, then reenable it...this doesn't work for me since I use an external Radius server, so my internal radius server is already off. Any thoughts on what else I might be able to try? Thank you for you videos...they have been very helpful!

maxcarreon
Автор

Is this why my offsite Synology cannot connect to my USG with L2TP, but my iPhone can? I can do Synology to Synology, but when I set up users in USG, the offsite NAS connection fails.

ScottMartinez
Автор

I must be ret... I can't create a new site. Do you have to be logged in locally?

laredotech
Автор

After watching this video, I’m struggling because I might have to recreate my entire Site/network. Is there any other option to undo the configuration using the new UI so it will work with the old UI. Is it possible to simply reset the USG to clear things or possibly complete the VPN config manually?

dougmiller
Автор

I have a problem with outgoing L2TP VPN connections, have a unifi network at home and I have unifi at work, when I try to connect to work using win 10 vpn client, it just does not work. Issue is with local unifi blocking outgoing vpn traffic, if I switch to mobile data the vpn works... anyone has a fix for this, Ive been digging through forums but no fix. I even switched from USG-3P to the UDM Pro and it still does not work...

dariokarnincic
Автор

I will try it. But Ubiquiti support are on my issu for 2 weeks asking logs and logs and logs. They also specified me to create the vpn using the new interface. Like always seam Ubiquiti support team doesn't know what to do. Willie you should apply as external consultant for them ;)

JesterQc
Автор

Theres almost no reason to use the new ui

MrMglass
Автор

The biggest problem is you can not have two windows computers connected from the same remote network. Apple has no issues but once one computer connects at the same location another can not connect at the same time

nubaus
Автор

Hey Willie, have you been able to go to something newer than l2tp for remote access VPNs? We have an EdgeRouter for our main router, and a UDM-Pro inside the LAN that I can NAT out for remote access. L2TP was okay until android killed it off in the new version 12. Now our doctors can't get in except from a windows PC. Thanks for what you do, brotha!

travismeeks
Автор

I cant get my Iphone l2tp vpn to work, it works on my PC

warrent
Автор

Overall just cannot use their Gateway's ever. The Client VPN is just not up to task. It is still a fundamental in Business and useful even with home setups. The sheer amount of ongoing support calls for L2TP/IPsec on windows is enough to drive you mad. Same on Meraki as well...even with Beta Anyconnect support we have been waiting for for 5 years.

innermotion
Автор

I don't have problems with synology VPN It Works great

damionmorley
Автор

This is now fixed in the new interface:).

So now you can just create vpn.. windows connects fine... Android won't though :(.

I can't find how to connect android yet.

lovol
Автор

Unifi have great switches and great APs, but stay away from the cloud keys, security gateways etc
Use a proper router/firewall as your gateway

d_must
Автор

I wish they would get rid of l2tp since some phones like Android 12 are removing it because it's such an old protocol, I would love to see them add wireguard support natively

resolutepixel
Автор

Now they took away pptp so that took away a work around

nubaus