ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    EdgeRouter L2TP VPN does not work with updated systems

    Scheduled Pinned Locked Moved IT Discussion
    edgeosedgeos 1.10.0ubntl2tpvpncipher
    13 Posts 4 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch
      last edited by JaredBusch

      So I posted this over on the Ubiquiti Community, but wanting more eyes on it.

      I have been unable to use L2TP since I ran upgrades and libreswan was upgraded to libreswan-3.21-1.fc26.x86_64. I currently have libreswan-3.23-1.fc27.x86_64. My router is an ERL running 1.10.0.

      Checking what was being offered, I see this.

      [user@hostname ~]$ sudo ./ike-scan.sh mv.ip.add.ress | grep SA
          SA=(Enc=3DES Hash=MD5 Group=2:modp1024 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=MD5 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=MD5 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=MD5 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=MD5 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=SHA2-384 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=SHA2-384 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=SHA2-384 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=SHA2-384 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=3DES Hash=SHA2-384 Group=20 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=MD5 Group=2:modp1024 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=MD5 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=MD5 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=MD5 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=MD5 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=SHA2-384 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=SHA2-384 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=SHA2-384 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=SHA2-384 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=128 Hash=SHA2-384 Group=20 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=MD5 Group=2:modp1024 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=MD5 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=MD5 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=MD5 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=MD5 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=SHA2-384 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=SHA2-384 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=SHA2-384 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=SHA2-384 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=192 Hash=SHA2-384 Group=20 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=MD5 Group=2:modp1024 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=MD5 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=MD5 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=MD5 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=MD5 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=SHA2-384 Group=5:modp1536 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=SHA2-384 Group=14:modp2048 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=SHA2-384 Group=15:modp3072 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=SHA2-384 Group=19 Auth=PSK LifeType=Seconds LifeDuration=28800)
          SA=(Enc=AES KeyLength=256 Hash=SHA2-384 Group=20 Auth=PSK LifeType=Seconds LifeDuration=28800)
      

      Network Manager's L2TP no longer supports such weak encryption.

      https://github.com/nm-l2tp/network-manager-l2tp/wiki/Known-Issues#weak-legacy-algorithms

      Legacy algorithms that are considered weak or broken are regularly removed from the default set of allowed algorithms with newer releases of strongSwan and Libreswan. As of strongSwan 5.4.0 and Libreswan 3.20, the above algorithms (apart from SHA1 and MODP1536 for Libreswan which still includes them for backwards compatibility) have been or in some cases already been removed from the default set of allowed algorithms.

      This post says that the L2TP ciphers are not configurable unless we drop to editing the scripts.

      https://community.ubnt.com/t5/EdgeMAX/L2TP-IPSec-default-negotiation-3DES-vs-AES-SHA1-vs-SHA2-etc/m-...

      This is huge problem, IMO.

      1 Reply Last reply Reply Quote 1
      • JaredBuschJ
        JaredBusch
        last edited by

        That github link contains this link.
        https://github.com/nm-l2tp/network-manager-l2tp#example-workaround-for-3des-sha1-and-modp1024-broken-algorithms
        Which says this.
        0_1519369560587_26c75501-ff5c-43ec-a549-e19f2f37321d-image.png

        I added that, but still no go.
        0_1519369649076_e7b00b39-c4cc-4f68-b352-571cbad9c743-image.png

        1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch
          last edited by

          Well shit maybe a problem with the kernel

          The NetworkManager maintainer replies on the Ubiquiti forum post I made.
          https://community.ubnt.com/t5/EdgeMAX/L2TP-unusable-on-Fedora/td-p/2254953

          1 Reply Last reply Reply Quote 1
          • JaredBuschJ
            JaredBusch
            last edited by

            Booted a VM to the Fedora 27 Workstation Live ISO.
            Used dnf to installed L2TP and it worked perfectly.

            The Live ISO uses kernel 4.13.9-300.

            This confirm that kernel 4.14 and 4.15 are doing something wrong and are breaking IPsec.

            dafyreD 1 Reply Last reply Reply Quote 2
            • dafyreD
              dafyre @JaredBusch
              last edited by

              @jaredbusch said in EdgeRouter L2TP VPN does not work with updated systems:

              Booted a VM to the Fedora 27 Workstation Live ISO.
              Used dnf to installed L2TP and it worked perfectly.

              The Live ISO uses kernel 4.13.9-300.

              This confirm that kernel 4.14 and 4.15 are doing something wrong and are breaking IPsec.

              You can block dnf from installing newer kernels until this is fixed if you need to.

              JaredBuschJ 1 Reply Last reply Reply Quote 0
              • JaredBuschJ
                JaredBusch @dafyre
                last edited by

                @dafyre said in EdgeRouter L2TP VPN does not work with updated systems:

                @jaredbusch said in EdgeRouter L2TP VPN does not work with updated systems:

                Booted a VM to the Fedora 27 Workstation Live ISO.
                Used dnf to installed L2TP and it worked perfectly.

                The Live ISO uses kernel 4.13.9-300.

                This confirm that kernel 4.14 and 4.15 are doing something wrong and are breaking IPsec.

                You can block dnf from installing newer kernels until this is fixed if you need to.

                I've long been on a kernel newer than 4.13

                1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato
                  last edited by

                  Was this the bug you were referring to?
                  https://bugzilla.redhat.com/show_bug.cgi?id=1526203
                  https://github.com/hwdsl2/setup-ipsec-vpn/issues/102
                  https://github.com/libreswan/libreswan/issues/140

                  JaredBuschJ 2 Replies Last reply Reply Quote 0
                  • JaredBuschJ
                    JaredBusch @dbeato
                    last edited by

                    @dbeato I'm not referencing any bug.
                    I am telling you it does not work on 4.15. So whatever that bug was involved with is not resolved currently.

                    Additionally the NetworkManager maintainer stated in his post on the Ubiquiti community that it was broke in 4.15 also.

                    0_1519767547410_2f862170-b67f-4bfc-ad3c-dbdf621b8b3f-image.png

                    1 Reply Last reply Reply Quote 1
                    • JaredBuschJ
                      JaredBusch @dbeato
                      last edited by JaredBusch

                      @dbeato said in EdgeRouter L2TP VPN does not work with updated systems:

                      Was this the bug you were referring to?
                      https://bugzilla.redhat.com/show_bug.cgi?id=1526203
                      https://github.com/hwdsl2/setup-ipsec-vpn/issues/102
                      https://github.com/libreswan/libreswan/issues/140

                      Your first link is semi related.

                      I have no idea wtf you are trying to prove with the second link.

                      The third link is only tangently related, but a follow up post on that links to the actual kernel commits that are the problem. But I have no idea how to know what is what from that level of in depth detail.
                      https://patchwork.ozlabs.org/patch/838470/

                      dbeatoD 1 Reply Last reply Reply Quote 0
                      • dbeatoD
                        dbeato @JaredBusch
                        last edited by

                        @jaredbusch said in EdgeRouter L2TP VPN does not work with updated systems:

                        @dbeato said in EdgeRouter L2TP VPN does not work with updated systems:

                        Was this the bug you were referring to?
                        https://bugzilla.redhat.com/show_bug.cgi?id=1526203
                        https://github.com/hwdsl2/setup-ipsec-vpn/issues/102
                        https://github.com/libreswan/libreswan/issues/140

                        Your first link is semi related.

                        I have no idea wtf you are trying to prove with the second link.

                        The third link is only tangently related, but a follow up post on that links to the actual kernel commits that are the problem. But I have no idea how to know what is what from that level of in depth detail.
                        https://patchwork.ozlabs.org/patch/838470/

                        The 2nd one deserved the WTF because is from 1/2017 so it is not related.

                        1 Reply Last reply Reply Quote 0
                        • FATeknollogeeF
                          FATeknollogee
                          last edited by FATeknollogee

                          @JaredBusch Does your L2TP work in Fedora 28?

                          I'm on 4.17.7-200 & can't get L2TP working (from my desktop)
                          I spin up a W10 vm & no problem getting it work

                          JaredBuschJ 1 Reply Last reply Reply Quote 0
                          • JaredBuschJ
                            JaredBusch @FATeknollogee
                            last edited by

                            @fateknollogee said in EdgeRouter L2TP VPN does not work with updated systems:

                            @JaredBusch Does your L2TP work in Fedora 28?

                            I'm on 4.17.7-200 & can't get L2TP working (from my desktop)
                            I spin up a W10 vm & no problem getting it work

                            It was working on two months ago or so it was working last month I have not tried it in a few weeks

                            1 Reply Last reply Reply Quote 0
                            • FATeknollogeeF
                              FATeknollogee
                              last edited by

                              Did you use the Libreswan or Strongswan setting in your previous post?

                              1 Reply Last reply Reply Quote 0
                              • 1 / 1
                              • First post
                                Last post