7800DX IPSEC/L2TP Passthrough Issues
Posted: Tue Oct 25, 2016 10:25 pm
Wondering if anyone can help. Like many I have an conceptual understanding of FW routing but truth is I probably don't truly get it which is why when the out of the box fails me I get into trouble
so I have done my best to break down what I have tested to help isolate
All literature suggested the 7800DX supports IPSEC/L2TP Pass through, however we can’t get the Billion 7800DX to pass-through L2TP to the windows servers.
Test setup is
- PC - Windows 10 Pro workstation with Standard Windows VPN Client using L2TP with custom Pre-shared Key
- Server - Server Windows 2012 R2 with standard RRAS: L2TP with pre-shared key
- Billion 7800DX Firmware 2.32e
- All tests performed after factory reset
Testing
Direct Test: PC > LAN > Server : PASS
Route Only Test : PC > eWAN on Billion > Server : PASS
- WAN FW and NAT disabled
Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP 1701, ESP, UDP 4500)
IPSEC Nat Traversal Enabled : Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP1701, ESP, UDP 4500)
- VPN IPSec Nat Traversal Enabled
IPSEC Nat Traversal Disabled : Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP 1701, ESP, UDP 4500)
- VPN IPSec Nat Traversal Enabled
ALG IPSec Disabled : Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP 1701, ESP, UDP 4500)
- VPN IPSec Nat Traversal Disabled
- ALG IPSec Disabled
DMZ Host : Set to Server : FAIL
One-One-Nat to Server
- PPTP : PASS
- L2TP : FAIL

All literature suggested the 7800DX supports IPSEC/L2TP Pass through, however we can’t get the Billion 7800DX to pass-through L2TP to the windows servers.
Test setup is
- PC - Windows 10 Pro workstation with Standard Windows VPN Client using L2TP with custom Pre-shared Key
- Server - Server Windows 2012 R2 with standard RRAS: L2TP with pre-shared key
- Billion 7800DX Firmware 2.32e
- All tests performed after factory reset
Testing
Direct Test: PC > LAN > Server : PASS
Route Only Test : PC > eWAN on Billion > Server : PASS
- WAN FW and NAT disabled
Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP 1701, ESP, UDP 4500)
IPSEC Nat Traversal Enabled : Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP1701, ESP, UDP 4500)
- VPN IPSec Nat Traversal Enabled
IPSEC Nat Traversal Disabled : Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP 1701, ESP, UDP 4500)
- VPN IPSec Nat Traversal Enabled
ALG IPSec Disabled : Firewall/Port Forward : PC > eWAN on Billion > WAN IP : FAIL
- WAN FW and NAT enabled
- NAT to Server (UDP500, UDP 1701, ESP, UDP 4500)
- VPN IPSec Nat Traversal Disabled
- ALG IPSec Disabled
DMZ Host : Set to Server : FAIL
One-One-Nat to Server
- PPTP : PASS
- L2TP : FAIL