Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    L2TP Server only allowing one VPN at a time

    Scheduled Pinned Locked Moved General pfSense Questions
    21 Posts 4 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      ruffle @stephenw10
      last edited by ruffle

      @stephenw10 Yes 1701 and No not under my control. All I get to setup on the LNS is the IP address to connect to and an ID (which PFSense doesn't use).

      If you look at the diagram on this link: https://www.aa.net.uk/voice-and-mobile/data-sims/relay-data-sims-your-own-network/ I think that makes it clear.

      The IOT device with one of these SIMs connects to the A&A LNS over the mobile networkl and that LNS connects to my PFSense L2TP server. The IOT device then authenticates with PAP/CHAP.

      Yes I'm running the PFSense L2TP server on my WAN port. If it makes any difference I actually have two PFSense boxen in a CARP setup but on the PFSense L2TP server config page I can't pick the CARP WAN interface so I'm running it on igb2.

      1 Reply Last reply Reply Quote 0
      • R
        ruffle
        last edited by

        If it's any help, here's the setup page on the A&A LNS for each SIM.
        aa-sim-setup.png

        1 Reply Last reply Reply Quote 0
        • R
          ruffle
          last edited by

          @stephenw10

          Sorry to bug you but do you think there's any hope of getting this fixed/working?

          If not I need to be looking for some alternate L2TP server as I'm under pressure to get this rolled out.

          Thanks.

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Sorry, we are flat out to get snapshots stable enough for public testing.

            Just to be clear each of these IoT devices has it's own SIM/mobile connection? But they all come into pfSense using the same source IP and source port?

            Steve

            R 1 Reply Last reply Reply Quote 0
            • R
              ruffle @stephenw10
              last edited by

              @stephenw10

              Got it in one :)

              Yes, they each have a SIM and each connect over the mobile network to the A&A LNS. The A&A LNS then connects to PFSense on port 1701. The A&A LNS tends to use the same IP for every connection.

              For the A&A LNS to PFSense L2TP connection I can set a hostname (aka login) and password (aka secret) for the L2TP connection as the screenshot shows although PFSense doesn't seem to use that info.

              Each SIM also has a 'dialing number'/ICCID but again PFSense doesn't seem to make use of that.

              .

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Hmm, but it's the individual IoT devices making the L2TP connection to pfSense?

                Not one L2TP tunnel that all the IoT devices use?

                I'm unclear how this can possibly work in the first instance because will all clients using the same source address and port the L2TP server has no way to know what traffic to send to which client.

                And I assume there must be some NAT happening somewhere since the IoT devices must at some level be using different IP addresses. How does that NAT device know which client to send packets to?

                There must be something I'm not understanding here because I can't see how that could ever work.

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  Among ISPs (IMHO) A&A and have got to be in the top 1%. It would definitely be worth giving their support a call about this.
                  But in addition to that overview diagram they have a load of detailed docs:
                  https://support.aa.net.uk/Category:L2TP_Handover

                  So in fact this is one L2TP tunnel with multiple ppp sessions across it.

                  I'm not sure if you can do that in pfSense directly. Not without some custom scripting perhaps.
                  I've never seen it done.

                  But the first thing to try would be to make sure you have the same hostname set for all clients. The docs there show that will create a single tunnel with multiple sessions across it which is what you need.

                  Steve

                  Steve

                  R 1 Reply Last reply Reply Quote 1
                  • R
                    ruffle @stephenw10
                    last edited by

                    @stephenw10

                    You Sir are a Genius a Gentleman and a Scholar!

                    Setting the hostname on the A&A SIM control page to the same for each device (well three so far but I'm excited and want to report back ASAP) works :-) :-) :-)

                    Never have thought of that in a million years.

                    Thanks muchly.

                    PS - Agree on A&A. Been using them for decades.

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      Awesome! Good to know that works. Let us know how it goes.

                      Steve

                      1 Reply Last reply Reply Quote 0
                      • B
                        billshih74 @bingo600
                        last edited by

                        @bingo600 I'm wondering is you have found solution to this? Mine problem is similar only I user Conezilla to clone my hdd with Debian 9 stretch, three of clients can be working by getting their private ip. The others get duplicate ip and I can't find any clue. Please let me know if you happen to know it.

                        1 Reply Last reply Reply Quote 0
                        • stephenw10S
                          stephenw10 Netgate Administrator
                          last edited by

                          Did you reply on the wrong thread? This looks completely unrelated (or spam).

                          Steve

                          bingo600B 1 Reply Last reply Reply Quote 0
                          • bingo600B
                            bingo600 @stephenw10
                            last edited by

                            @stephenw10
                            The answer to the clonezilla issue above has to be 42

                            And could "smell" of a wrong thread or as you mentioned. Someone "upping" their post count, in order to .......

                            /Bingo

                            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                            pfSense+ 23.05.1 (ZFS)

                            QOTOM-Q355G4 Quad Lan.
                            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                            1 Reply Last reply Reply Quote 0
                            • B
                              billshih74
                              last edited by

                              sorry Im new to this forum, could someone tell me where to put this issue so that I can find my solution? Thanks.

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Is this an L2TP problem? Open a thread General pfSense Questions if you're unsure. We can always move it. Give as much details about the problem as you can.

                                Steve

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.