Article ID: 247231 - Last Review: February 28, 2007 - Revision: 3.2 Event ID 20111, Error 792 or Error 781 When Establishing an L2TP/IPSec ConnectionThis article was previously published under Q247231 SYMPTOMS
When you attempt to manually establish a Layer 2 Tunneling Protocol (L2TP)/IP Security Protocol (IPSec) connection with a Windows 2000-based server by using the Routing and Remote Access snap-in, you may be unable to do so, and the initiator computer may display the following error message:
Routing and Remote Access An error occurred during connection of the interface. The L2TP connection attempt failed because security negotiation timed out.
Source: RemoteAccess Event ID: 20111 Description: A Demand Dial connection to the remote interface <interface name> on port VPNx-y was successfully initiated but failed to complete successfully because of the following error: The L2TP connection attempt failed because security negotiation timed out. When you attempt to establish an L2TP/IPSec connection by using Network and Dial-up Connections, you are unable to do so, and the initiator computer may display the following error message:
Error Connecting to <Connectoid Name> Connecting to <IP address>... Error 792: The L2TP connection attempt failed because security negotiation timed out.
-or-
Error Connecting to <Connectoid Name> Connecting to <IP address>... Error 781: Encryption failed because no valid certificate was found. CAUSE
This issue can occur because of one of the following reasons:
RESOLUTION
To resolve this issue, do one of the following:
MORE INFORMATION
When you stop and start the IPSec Policy Agent service without stopping and starting the Routing and Remote Access service, the automatic IPSec policy that is usually created for the L2TP/IPSec connection is not created and the connections are not successful.
If you stop the IPSec Policy Agent service while you have active tunnel connections without first stopping the Routing and Remote Access service, the tunnels are unsecured, and data is exposed in the clear. It is recommended that you stop active tunnel connections before you stop the IPSec Policy Agent service. Note that stopping the IPSec Policy Agent and the Routing and Remote Access services may remove filters that are critical to protecting your computers, and to prevent this downtime in security, it is recommended that you disconnect the network cable.
| Article Translations
|

Back to the top
