Troubleshooting L2TP 1621[LNS-isp-aaa.net] ip pool 1 10.0.2.10 10.0.2.100[LNS-isp-aaa.net] quit# Create two virtual interface templates.[LNS]interface virtual-template 1[LNS-Virtual-Template1] ip address 1.1.2.2 255.255.255.0[LNS-Virtual-Template1] remote address pool 1[LNS-Virtual-Template1] ppp authentication-mode chap domain bbb.net[LNS-Virtual-Template1] quit[LNS] interface virtual-template 2[LNS-Virtual-Template2] ip address 1.1.2.2 255.255.255.0[LNS-Virtual-Template2] remote address pool 1[LNS-Virtual-Template2] ppp authentication-mode chap domain aaa.net[LNS-Virtual-Template2] quit# Create two L2TP groups.[LNS] l2tp-group 3[LNS-l2tp3] tunnel authentication[LNS-l2tp3] allow l2tp virtual-template 1 remote LAC domain aaa.net[LNS-l2tp3] tunnel password simple 12345[LNS-l2tp3] quit[LNS] l2tp-group 4[LNS-l2tp4] tunnel authentication[LNS-l2tp4] allow l2tp virtual-template 2 remote LAC domain bbb.net[LNS-l2tp4] tunnel password simple 12345If the RADIUS authentication is required on the LNS, modifying the AAAconfigurations as needed. For AAA configuration details, refer to “ConfiguringAAA” on page 1761.Complicated NetworkApplicationA security gateway can serve as an LAC and an LNS simultaneously. Additionally, ithas the ability to support more than one incoming call. Should there be enoughmemory and physical lines, L2TP can receive and make multiple calls at the sametime. You can refer to the above examples for complicated network configuration.Note that many L2TP applications rely on static routes to initiate connectionrequests.Troubleshooting L2TP The VPN connection setup process is rather complicated. The following presentsan analysis of some common faults occurred in the process. Beforetroubleshooting the VPN, make sure that the LAC and LNS are connected properlyacross the public network.Symptom 1:Users cannot log in.Analysis and solution:Possible reasons for login failure are as follows:1 Tunnel setup failure. In this case, it is possible that:■ The address of the LNS is set incorrectly on the LAC.