Packet dropped - fails to handle L2TP pkt

Description

When any windows client tries to connect to the SonicWall using built-in windows VPN feature (L2TP), sometimes SonicWall drops the L2TP packets on destination port UDP 1701 with a module ID and drop code. The drop code changes according to the firmware versions and is about "Packet dropped - fails to handle L2TP pkt".

Below error messages would appear on the client machine.

Image  Image

Cause

By default, the windows VPN uses certificate for authentication. In SonicWall, pre shared secret could be configured for L2TP authentication. SonicWall is also not configured to use certificate for authentication. When the L2TP traffic from client hits SonicWall, Security Association (SA) would not include certificate information and more over in the windows client VPN connection setup is configured (by default) to use certificate for authentication but the appropriate certificate is not installed on the client.

Resolution

Step 1: In the client machine, go to the L2TP VPN Connection Properties window.
Step 2: Switch to Security tab and ensure Type of VPN is set to "Layer 2 Tunneling Protocol with IPsec (L2TP/IPsec)".
Step 3: Click on Advanced Settings.
Image
Step 4: In the Advanced Properties window, select the option "Use pre shared key for authentication" and specify the pre shared key value in Key field which is configured on SonicWall WAN Group VPN.
Image
Step 5: Click OK.

  • After clicking OK and when attempted to look at the pre shared secret value, the Key field should look alike the below screenshot.

Image
How to Test:

  • Initiate the VPN connection and this time the connection should be successful with below screenshot shown VPN connection states.

Image

Image
Image

Related Articles

  • SonicOS 8.1.0 FAQ
    Read More
  • SonicWall GEN8 TZs and GEN8 NSas Settings Migration
    Read More
  • Getting started with SonicWall firewalls
    Read More
not finding your answers?