This article explains how to configure a L2TP VPN in order to connect from Android Devices.
Deployment Steps:
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
WanGroupVPN settings

|
| Authentication Method: "IKE using Preshared Secret" Name: WAN GroupVPN Shared Secret: type a passphrase (you will enter this is into the Droid later) |
NOTE: To successfully establish a VPN tunnel the L2TP (VPN) client and the Remote VPN device must agree upon the same set of Proposals/Transform Payloads (differs from client to client), please refer the following article for complete details: List of IPSec and L2TP client proposals
![]() | IKE (Phase 1) Proposal DH Group = Group 2 IPSec (Phase 2) Proposal Protocol = ESP Authentication = SHA1 |
![]() | Enable Windows Networking (NetBIOS) Broadcast = checked Require authentication of VPN clients by XAUTH = Checked |
![]() | Cache XAUTH User Name and Password on Client: Single Session or Always |
L2TP Server Settings




Make the user part of the Group "Trusted Users" on the Groups tab.
In the VPN Access list – as a minimum add these networks: LAN Subnets/LAN Primary Subnet and L2TP IP Pool.

Android Settings
Configure the Android: Go the settings | More connection settings
![]() | ![]() |
![]() | ![]() |
The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.
|
| Authentication Method: "IKE using Preshared Secret" Name: WAN GroupVPN Shared Secret: type a passphrase (you will enter this is into the Droid later) |
Second Tab "Proposals"
NOTE: To successfully establish a VPN tunnel the L2TP (VPN) client and the Remote VPN device must agree upon the same set of Proposals/Transform Payloads (differs from client to client), please refer the following article for complete details: List of IPSec and L2TP client proposals
![]() | IKE (Phase 1) Proposal DH Group = Group 2 IPSec (Phase 2) Proposal Protocol = ESP Authentication = SHA1 |
"Advanced" tab![]() | Enable Windows Networking (NetBIOS) Broadcast = checked Require authentication of VPN clients by XAUTH = Checked |
"Client" tab
![]() | Cache XAUTH User Name and Password on Client: Single Session or Always |
L2TP Server Settings
NOTE: This is the same group you select on the Advanced tab in the WAN GroupVPN settings. 

![]() | ![]() |
Android Settings
Configure the Android. Go the setting APP page and select the Settings icon.
![]() | ![]() |
![]() | ![]() |