Monday, January 30, 2017

Configuring L2TP VPN on Zyxel USG 60 for Chromebook / ChomeOS compatibility

For a couple of years I have had no problem connecting to my office VPN from my Chromebooks. Prior to departing for a long trip I decided to just double-check that all was well. Unfortunately, it wasn't. I could no longer connect to the VPN from either of my Chromebooks, even though I still connected successfully from Windows and from Android. I assumed that Google changed something, but as it turns out, it was probably a change that I made in the USG that caused the problem.

After months of frustration, I came upon an blog post that detailed the ipsec VPN configuration settings on a Fortigate router needed to work with the Chromebook's built-in VPN capability.

https://dbssolutions.freshdesk.com/support/solutions/articles/196790-how-to-configure-a-fortigate-ipsec-vpn-for-google?_utm_source=1-2-2

L2TP depends upon underlying ipsec protocols so I compared mine on the USG to those documented in the post above.

Looking at the IPSEC Phase 2 configuration, I saw that the policies did not match those I was using. Once I changed them to match those in the article, the Chromebook connected no problem. The results suggest that the Chromebook doesn't like SHA authentication. A while back I had changed a Zyxel default policy that specified MD5 authentication to SHA. Once I re-created a policy that uses MD5 authentication instead, the VPN link was established successfully and quickly. Here are my new working settings:


3 comments:

  1. My friend also had the same problem of connecting to VPN from his Chromebooks and he was really concerned about his internet privacy. Then he found hidemyass vpn review online and till that day he is using the same VPN. Hope it helps.

    ReplyDelete
  2. This is such a great resource that you are providing and you give it away for free. I love seeing blog that understand the value of providing a quality resource for free. super vpn for windows 10

    ReplyDelete