No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


CLI-based Configuration Guide - VPN

AR100, AR120, AR150, AR160, AR200, AR1200, AR2200, AR3200, and AR3600 V200R010

This document describes VPN features on the device and provides configuration procedures and configuration examples.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
User Failed to Dial Up to the LNS

User Failed to Dial Up to the LNS

Fault Description

A remote user uses the built-in dial-up software of Windows XP to initiate L2TP connections to the LNS in the enterprise headquarters. However, the dialup fails.


Before handling this fault, ensure that a reachable route exists between the remote user and the LNS.

The possible causes are:
  • The user information differs from that configured on the LNS.

    In the AAA view, you can check user information configured on the LNS.

  • The IP address pool on the LNS is incorrectly configured.

    No gateway address is specified in the IP address pool or the specified gateway address is incorrect. Run the gateway-list ip-address &<1-8> command to specify the IP address of the virtual template interface as the gateway address.

  • The authentication modes on the PC and the LNS are different.

    Run the display l2tp-group [ group-number ] command on the LNS to check the TunnelAuth field to see whether tunnel authentication is enabled. Windows XP does not support tunnel authentication. If the remote user supports tunnel authentication, check whether the authentication password of the user is the same as that configured in the L2TP group view.

  • PPP negotiation parameters are not consistent on the two ends.

    In the VT interface view, check whether the PPP authentication mode configured on the LNS is pap or chap. Run the display l2tp-group [ group-number ] command to check the ForceChap field to see whether mandatory CHAP authentication is enabled. If the mandatory CHAP authentication is enabled, the authentication mode must be chap in the VT interface view. Check the L2TP connection attributes on the PC to ensure that PAP and CHAP are selected.

    Figure 1-25  L2TP connection attributes

Updated: 2019-08-07

Document ID: EDOC1100033725

Views: 150900

Downloads: 367

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Previous Next