NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
train_wreck
Aug 31, 2016Luminary
L2TP/IPsec - Android to FVS336Gv3 - "the length of the isakmp header is too big"
I am using the guide I made to configure L2TP/IPsec on the FVS336Gv3: https://community.netgear.com/t5/VPN-Firewalls/FVS336Gv3-L2TP-IPsec-on-Windows-10/m-p/1063257#M4362 Windows clients are ...
train_wreck
Jun 05, 2017Luminary
Yes, it expects Mode Config. Basically, you can follow that guide, but select the "Edge Device" radio button under "XAuth Configuration", then add a user on the "Users" page of type "IPSEC VPN User". Be aware that this will break compatibiltiy with the Windows built-in VPN client, since it doesn't support XAuth. I have found limited success on Windows using the "Shrewsoft" free VPN client, but it has issues with DPD randomly failing, and also seems to be abandonded (last update in 2013). I have been looking into the "Green Bow" Windows VPN client recently, but haven't finished evaluating it. BTW, all of this madness is why many people are moving to OpenVPN, or historically have used proprietary VPN clients. For decades, built-in IPsec clients have ranged from passable to absolutely horrendous, in terms of compatibility and performance. OpenVPN seems to be the future here.
As far as encryption algorithms, my S7 didn't really seem to care, between 3DES-SHA1 or AES128/192/256-SHA1 on either IKE (phase 1).= or Mode Config (phase 2). I have always used DH group 5, but I imagine it will accept no DH group as well.
vpnman
Jun 08, 2017Guide
Thanks. It worked.
Regarding OpenVPN, I believe it'll be the de-facto VPN solution for consumer router products. OpenVPN is propelled by it's open source community and comparatively low burden on consumer router makers to incorporate to their products. I think all these madness on IPSEC VPN is due to efforts by networking gear makers to monetize when selling to business on both VPN server side, client side and services. I think the interesting question is.... the small business customers (where FVS336GV3 or RV320/340 is aiming at)... they want the simplicity/free aspect of OpenVPN but need performance and flexibility of IPSEC VPN.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!