Page 1 of 1

IPsec / L2TP woe upon Android and Windows

Posted: Fri Apr 04, 2025 3:52 pm
by panpanrobot
Hi SoftEther community,

I'm able to connect to my SoftEther VPN server through the proprietary protocol but not using IPsec / L2TP. Can you pinpoint a problem in my setup? (All names/passwords are substituted except the hub name.)
  • In the router in front of the server, I have opened ports 500, 4500, and 1701 UDP (I also opened ESP and AH for testing with no luck).
  • In the SERVER (Windows 10), I have unblocked vpnsmgr_x64.exe and vpnserver_x64.exe.
  • I checked "Enable L2TP Server Function (L2TP over IPsec)" with the IPsec PSK of "vpn".
  • My hub, "VPN_Home", has a user "panpan" with password authentication "password1". "VPN_Home" is default.
  • The dynamic DNS is panpan.softether.net
  • On the CLIENT Windows 11, I've got the server DNS, L2TP/IPsec with PSA, PSA, username (with no "@VPN_Home" or "VPN_Home/panpan") and password, proxy set to none (auto didn't work either), Allowed protocols are CHAP and MS-CHAP v2.
  • On the CLIENT Android all the same except the forwarding routes has "0.0.0.0/0".
On Windows 11 client, I tried the AssumeUDPEncapsulationContextOnSendRule registry fix with no luck. On Android, I tried an app instead. No luck.

I'm at my wit's end! Any ideas?

Re: IPsec / L2TP woe upon Android and Windows

Posted: Fri Apr 04, 2025 11:54 pm
by solo
Disable any IPsec/L2TP function on the server computer which might conflict with SoftEther VPN Server's IPsec/L2TP function. If the UDP ports (500, 4500 and 1701) conflicts with other programs, IPsec communication will not work well.
For example, disable the "Routing and Remote Access" service on Windows Server.
https://www.softether.org/4-docs/2-howt ... .2F_L2TPv3

Re: IPsec / L2TP woe upon Android and Windows

Posted: Mon Apr 07, 2025 4:24 pm
by panpanrobot
Thanks for the idea, solo. The "Routing and Remote Access" service was offline. I don't think any other services are using the ports. Any other ideas?