<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-4436</id>
	<title>Nabble - Poptop</title>
	<updated>2009-12-19T07:25:50Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Poptop-f4436.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Poptop-f4436.html" />
	<subtitle type="html">Poptop is an open source implementation of a PPTP server. Running under x86 or embedded Motorola ColdFire architectures Poptop provides full interoperability with the Microsoft PPTP VPN client. Poptop home is &lt;a href=&quot;http://sourceforge.net/projects/poptop/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26855888</id>
	<title>Re: Tunnel stops working after a while, LCP ProtRej</title>
	<published>2009-12-19T07:25:50Z</published>
	<updated>2009-12-19T07:25:50Z</updated>
	<author>
		<name>Gianluca Varenni</name>
	</author>
	<content type="html">It's a remote machine and I'm not in the office right now. Also, it 
&lt;br&gt;guarantees connectivity to the whole office. In general for a production 
&lt;br&gt;machine I prefer to install only deb package, no recompiling unless it's an 
&lt;br&gt;extreme situation.
&lt;br&gt;&lt;br&gt;I will probably wait until I get back to the office.
&lt;br&gt;&lt;br&gt;Have a nice day
&lt;br&gt;GV
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----- 
&lt;br&gt;From: &amp;quot;Jorge Bastos&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855888&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mysql.jorge@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &amp;quot;'Gianluca Varenni'&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855888&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gianluca.varenni@...&lt;/a&gt;&amp;gt;; 
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855888&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;poptop-server@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Sent: Saturday, December 19, 2009 6:42 AM
&lt;br&gt;Subject: RE: [Poptop-server] Tunnel stops working after a while, LCP ProtRej
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt; I just checked, and there is no official deb package for kernel 2.6.36,
&lt;br&gt;&amp;gt;&amp;gt; the
&lt;br&gt;&amp;gt;&amp;gt; latest available one is a 2.6.18 :-(
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Can't you compile it, or it's a remote machine?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855888&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Tunnel-stops-working-after-a-while%2C-LCP-ProtRej-tp26853769p26855888.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26855562</id>
	<title>Re: Tunnel stops working after a while, LCP ProtRej</title>
	<published>2009-12-19T06:42:29Z</published>
	<updated>2009-12-19T06:42:29Z</updated>
	<author>
		<name>Jorge Bastos</name>
	</author>
	<content type="html">&amp;gt; I just checked, and there is no official deb package for kernel 2.6.36,
&lt;br&gt;&amp;gt; the
&lt;br&gt;&amp;gt; latest available one is a 2.6.18 :-(
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;Can't you compile it, or it's a remote machine?
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855562&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Tunnel-stops-working-after-a-while%2C-LCP-ProtRej-tp26853769p26855562.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26855559</id>
	<title>Re: Tunnel stops working after a while, LCP ProtRej</title>
	<published>2009-12-19T06:41:14Z</published>
	<updated>2009-12-19T06:41:14Z</updated>
	<author>
		<name>Gianluca Varenni</name>
	</author>
	<content type="html">I just checked, and there is no official deb package for kernel 2.6.36, the 
&lt;br&gt;latest available one is a 2.6.18 :-(
&lt;br&gt;&lt;br&gt;Thanks anyway
&lt;br&gt;&lt;br&gt;GV
&lt;br&gt;&lt;br&gt;&lt;br&gt;----- Original Message ----- 
&lt;br&gt;From: &amp;quot;Jorge Bastos&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855559&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mysql.jorge@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &amp;quot;'Gianluca Varenni'&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855559&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gianluca.varenni@...&lt;/a&gt;&amp;gt;; 
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855559&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;poptop-server@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Sent: Saturday, December 19, 2009 6:05 AM
&lt;br&gt;Subject: RE: [Poptop-server] Tunnel stops working after a while, LCP ProtRej
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; It's a debian 4.0, I will see if I can still update the kernel package
&lt;br&gt;&amp;gt;&amp;gt; without breaking everything. Do you think that is the culprit?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Maybe,
&lt;br&gt;&amp;gt; I have similar situation, with clients connection from slow connections
&lt;br&gt;&amp;gt; including me, and that never happen or anyone complained.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855559&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Tunnel-stops-working-after-a-while%2C-LCP-ProtRej-tp26853769p26855559.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26855301</id>
	<title>Re: Tunnel stops working after a while, LCP ProtRej</title>
	<published>2009-12-19T06:05:30Z</published>
	<updated>2009-12-19T06:05:30Z</updated>
	<author>
		<name>Jorge Bastos</name>
	</author>
	<content type="html">&amp;gt; 
&lt;br&gt;&amp;gt; It's a debian 4.0, I will see if I can still update the kernel package
&lt;br&gt;&amp;gt; without breaking everything. Do you think that is the culprit?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;Maybe,
&lt;br&gt;I have similar situation, with clients connection from slow connections
&lt;br&gt;including me, and that never happen or anyone complained.
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26855301&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Tunnel-stops-working-after-a-while%2C-LCP-ProtRej-tp26853769p26855301.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26854562</id>
	<title>Re: Tunnel stops working after a while, LCP ProtRej</title>
	<published>2009-12-19T04:04:13Z</published>
	<updated>2009-12-19T04:04:13Z</updated>
	<author>
		<name>Gianluca Varenni</name>
	</author>
	<content type="html">It's a debian 4.0, I will see if I can still update the kernel package 
&lt;br&gt;without breaking everything. Do you think that is the culprit?
&lt;br&gt;&lt;br&gt;GV
&lt;br&gt;&lt;br&gt;----- Original Message ----- 
&lt;br&gt;From: &amp;quot;Jorge Bastos&amp;quot; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26854562&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;mysql.jorge@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26854562&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;poptop-server@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Sent: Saturday, December 19, 2009 3:21 AM
&lt;br&gt;Subject: Re: [Poptop-server] Tunnel stops working after a while, LCP ProtRej
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt; Server:
&lt;br&gt;&amp;gt;&amp;gt; pptpd 1.3.4
&lt;br&gt;&amp;gt;&amp;gt; pppd &amp;nbsp;2.4.4
&lt;br&gt;&amp;gt;&amp;gt; Kernel 2.6.18-6-686
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Client
&lt;br&gt;&amp;gt;&amp;gt; Windows XP SP3 and Windows Vista
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any ideas what could cause this problem?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Do you have opportunity to update the kernel to 2.6.32?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt; This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;&amp;gt; Take advantage of Verizon's best-in-class app development support
&lt;br&gt;&amp;gt; A streamlined, 14 day to market process makes app distribution fast and 
&lt;br&gt;&amp;gt; easy
&lt;br&gt;&amp;gt; Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26854562&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&amp;nbsp;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26854562&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Tunnel-stops-working-after-a-while%2C-LCP-ProtRej-tp26853769p26854562.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26854307</id>
	<title>Re: Tunnel stops working after a while, LCP ProtRej</title>
	<published>2009-12-19T03:21:18Z</published>
	<updated>2009-12-19T03:21:18Z</updated>
	<author>
		<name>Jorge Bastos</name>
	</author>
	<content type="html">&amp;gt; Server:
&lt;br&gt;&amp;gt; pptpd 1.3.4
&lt;br&gt;&amp;gt; pppd &amp;nbsp;2.4.4
&lt;br&gt;&amp;gt; Kernel 2.6.18-6-686
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Client
&lt;br&gt;&amp;gt; Windows XP SP3 and Windows Vista
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Any ideas what could cause this problem?
&lt;br&gt;&lt;br&gt;&lt;br&gt;Do you have opportunity to update the kernel to 2.6.32?
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26854307&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Tunnel-stops-working-after-a-while%2C-LCP-ProtRej-tp26853769p26854307.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26853769</id>
	<title>Tunnel stops working after a while, LCP ProtRej</title>
	<published>2009-12-19T01:40:17Z</published>
	<updated>2009-12-19T01:40:17Z</updated>
	<author>
		<name>Gianluca Varenni</name>
	</author>
	<content type="html">I have a problem with my pptpd installation, that started happening when my 
&lt;br&gt;users connect from far away locations with a really slow link (the server is 
&lt;br&gt;in california, the clients are in europe on a DSL link with some packet 
&lt;br&gt;drops every now and then).
&lt;br&gt;&lt;br&gt;The pptpd connection works for a bit and then it stops. This seems to happen 
&lt;br&gt;more frequently when the client is downloading/uploading big files on the 
&lt;br&gt;VPN.
&lt;br&gt;&lt;br&gt;The log is below.
&lt;br&gt;&lt;br&gt;As you can see, after a certain time pppd receives garbage and sends LCP 
&lt;br&gt;ProtRej packets.
&lt;br&gt;&lt;br&gt;Server:
&lt;br&gt;pptpd 1.3.4
&lt;br&gt;pppd &amp;nbsp;2.4.4
&lt;br&gt;Kernel 2.6.18-6-686
&lt;br&gt;&lt;br&gt;Client
&lt;br&gt;Windows XP SP3 and Windows Vista
&lt;br&gt;&lt;br&gt;Any ideas what could cause this problem?
&lt;br&gt;&lt;br&gt;Have a nice day
&lt;br&gt;GV
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Dec 19 00:21:46 evilside pppd[27039]: using channel 326
&lt;br&gt;Dec 19 00:21:46 evilside pppd[27039]: sent [LCP ConfReq id=0x1 &amp;lt;asyncmap 
&lt;br&gt;0x0&amp;gt; &amp;lt;auth chap MS-v2&amp;gt; &amp;lt;magic 0x2c017766&amp;gt; &amp;lt;pcomp&amp;gt; &amp;lt;accomp&amp;gt;]
&lt;br&gt;Dec 19 00:21:46 evilside pppd[27039]: rcvd [LCP ConfReq id=0x0 &amp;lt;mru 1400&amp;gt; 
&lt;br&gt;&amp;lt;magic 0x522857e4&amp;gt; &amp;lt;pcomp&amp;gt; &amp;lt;accomp&amp;gt; &amp;lt;callback CBCP&amp;gt;]
&lt;br&gt;Dec 19 00:21:46 evilside pppd[27039]: sent [LCP ConfRej id=0x0 &amp;lt;callback 
&lt;br&gt;CBCP&amp;gt;]
&lt;br&gt;Dec 19 00:21:47 evilside pppd[27039]: rcvd [LCP ConfReq id=0x1 &amp;lt;mru 1400&amp;gt; 
&lt;br&gt;&amp;lt;magic 0x522857e4&amp;gt; &amp;lt;pcomp&amp;gt; &amp;lt;accomp&amp;gt;]
&lt;br&gt;Dec 19 00:21:47 evilside pppd[27039]: sent [LCP ConfAck id=0x1 &amp;lt;mru 1400&amp;gt; 
&lt;br&gt;&amp;lt;magic 0x522857e4&amp;gt; &amp;lt;pcomp&amp;gt; &amp;lt;accomp&amp;gt;]
&lt;br&gt;Dec 19 00:21:49 evilside pppd[27039]: sent [LCP ConfReq id=0x1 &amp;lt;asyncmap 
&lt;br&gt;0x0&amp;gt; &amp;lt;auth chap MS-v2&amp;gt; &amp;lt;magic 0x2c017766&amp;gt; &amp;lt;pcomp&amp;gt; &amp;lt;accomp&amp;gt;]
&lt;br&gt;Dec 19 00:21:49 evilside pppd[27039]: rcvd [LCP ConfAck id=0x1 &amp;lt;asyncmap 
&lt;br&gt;0x0&amp;gt; &amp;lt;auth chap MS-v2&amp;gt; &amp;lt;magic 0x2c017766&amp;gt; &amp;lt;pcomp&amp;gt; &amp;lt;accomp&amp;gt;]
&lt;br&gt;Dec 19 00:21:49 evilside pppd[27039]: sent [LCP EchoReq id=0x0 
&lt;br&gt;magic=0x2c017766]
&lt;br&gt;Dec 19 00:21:49 evilside pppd[27039]: sent [CHAP Challenge id=0xdc 
&lt;br&gt;&amp;lt;f6f7816fc775bd1039244bb862b6340a&amp;gt;, name = &amp;quot;pptpd&amp;quot;]
&lt;br&gt;Dec 19 00:21:49 evilside pppd[27039]: rcvd [LCP Ident id=0x2 
&lt;br&gt;magic=0x522857e4 &amp;quot;MSRASV5.20&amp;quot;]
&lt;br&gt;Dec 19 00:21:49 evilside pppd[27039]: rcvd [LCP Ident id=0x3 
&lt;br&gt;magic=0x522857e4 &amp;quot;MSRAS-0-TEST&amp;quot;]
&lt;br&gt;Dec 19 00:21:49 evilside pppd[27039]: rcvd [LCP Ident id=0x4 
&lt;br&gt;magic=0x522857e4 
&lt;br&gt;&amp;quot;\037\025D\023A\37777777621IL\37777777600\37777777611\37777777731\024 
&lt;br&gt;\37777777710\022\37777777753&amp;quot;]
&lt;br&gt;Dec 19 00:21:52 evilside pppd[27039]: sent [CHAP Challenge id=0xdc 
&lt;br&gt;&amp;lt;f6f7816fc775bd1039244bb862b6340a&amp;gt;, name = &amp;quot;pptpd&amp;quot;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: rcvd [CHAP Response id=0xdc 
&lt;br&gt;&amp;lt;81ef9788b072f454b85ee5d46177e97b0000000000000000c89d2eaccae4c457bc4c9c602f5335c9784a7f435f23fa4e00&amp;gt;, 
&lt;br&gt;name = &amp;quot;USERXXX&amp;quot;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: RADATTR plugin wrote 8 line(s) to file 
&lt;br&gt;/var/run/radattr.ppp3.
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: sent [CHAP Success id=0xdc 
&lt;br&gt;&amp;quot;S=05095606B26E93C608D0C64E4B827EFFB75DE695&amp;quot;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: sent [CCP ConfReq id=0x1 &amp;lt;mppe +H -M 
&lt;br&gt;+S -L -D -C&amp;gt;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: rcvd [IPV6CP ConfReq id=0x5 &amp;lt;addr 
&lt;br&gt;fe80::b836:207a:8b56:f500&amp;gt;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: sent [LCP ProtRej id=0x2 80 57 01 05 
&lt;br&gt;00 0e 01 0a b8 36 20 7a 8b 56 f5 00]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: rcvd [CCP ConfReq id=0x6 &amp;lt;mppe +H -M 
&lt;br&gt;+S -L -D -C&amp;gt;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: sent [CCP ConfAck id=0x6 &amp;lt;mppe +H -M 
&lt;br&gt;+S -L -D -C&amp;gt;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: rcvd [IPCP ConfReq id=0x7 &amp;lt;addr 
&lt;br&gt;0.0.0.0&amp;gt; &amp;lt;ms-dns1 0.0.0.0&amp;gt; &amp;lt;ms-wins 0.0.0.0&amp;gt; &amp;lt;ms-dns3 0.0.0.0&amp;gt; &amp;lt;ms-wins 
&lt;br&gt;0.0.0.0&amp;gt;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: sent [IPCP TermAck id=0x7]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: rcvd [CCP ConfAck id=0x1 &amp;lt;mppe +H -M 
&lt;br&gt;+S -L -D -C&amp;gt;]
&lt;br&gt;Dec 19 00:21:53 evilside pppd[27039]: sent [IPCP ConfReq id=0x1 &amp;lt;compress VJ 
&lt;br&gt;0f 01&amp;gt; &amp;lt;addr 192.168.77.67&amp;gt;]
&lt;br&gt;Dec 19 00:21:54 evilside pppd[27039]: rcvd [IPCP ConfRej id=0x1 &amp;lt;compress VJ 
&lt;br&gt;0f 01&amp;gt;]
&lt;br&gt;Dec 19 00:21:54 evilside pppd[27039]: sent [IPCP ConfReq id=0x2 &amp;lt;addr 
&lt;br&gt;X.X.X.X&amp;gt;]
&lt;br&gt;Dec 19 00:21:54 evilside pppd[27039]: rcvd [IPCP ConfAck id=0x2 &amp;lt;addr 
&lt;br&gt;X.X.X.X&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: sent [IPCP ConfReq id=0x2 &amp;lt;addr 
&lt;br&gt;X.X.X.X&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: rcvd [IPCP ConfReq id=0x8 &amp;lt;addr 
&lt;br&gt;0.0.0.0&amp;gt; &amp;lt;ms-dns1 0.0.0.0&amp;gt; &amp;lt;ms-wins 0.0.0.0&amp;gt; &amp;lt;ms-dns3 0.0.0.0&amp;gt; &amp;lt;ms-wins 
&lt;br&gt;0.0.0.0&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: sent [IPCP ConfNak id=0x8 &amp;lt;addr 
&lt;br&gt;y.y.y.y&amp;gt; &amp;lt;ms-dns1 z.z.z.z&amp;gt; &amp;lt;ms-wins z.z.z.z&amp;gt; &amp;lt;ms-dns3 z.z.z.z&amp;gt; &amp;lt;ms-wins 
&lt;br&gt;z.z.z.z&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: rcvd [IPCP ConfAck id=0x2 &amp;lt;addr 
&lt;br&gt;X.X.X.X&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: rcvd [IPCP ConfReq id=0x9 &amp;lt;addr 
&lt;br&gt;0.0.0.0&amp;gt; &amp;lt;ms-dns1 0.0.0.0&amp;gt; &amp;lt;ms-wins 0.0.0.0&amp;gt; &amp;lt;ms-dns3 0.0.0.0&amp;gt; &amp;lt;ms-wins 
&lt;br&gt;0.0.0.0&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: sent [IPCP ConfNak id=0x9 &amp;lt;addr 
&lt;br&gt;y.y.y.y&amp;gt; &amp;lt;ms-dns1 z.z.z.z&amp;gt; &amp;lt;ms-wins z.z.z.z&amp;gt; &amp;lt;ms-dns3 z.z.z.z&amp;gt; &amp;lt;ms-wins 
&lt;br&gt;z.z.z.z&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: rcvd [IPCP ConfReq id=0xa &amp;lt;addr 
&lt;br&gt;y.y.y.y&amp;gt; &amp;lt;ms-dns1 z.z.z.z&amp;gt; &amp;lt;ms-wins z.z.z.z&amp;gt; &amp;lt;ms-dns3 z.z.z.z&amp;gt; &amp;lt;ms-wins 
&lt;br&gt;z.z.z.z&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: sent [IPCP ConfAck id=0xa &amp;lt;addr 
&lt;br&gt;y.y.y.y&amp;gt; &amp;lt;ms-dns1 z.z.z.z&amp;gt; &amp;lt;ms-wins z.z.z.z&amp;gt; &amp;lt;ms-dns3 z.z.z.z&amp;gt; &amp;lt;ms-wins 
&lt;br&gt;z.z.z.z&amp;gt;]
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: Script /etc/ppp/ip-up started (pid 
&lt;br&gt;27043)
&lt;br&gt;Dec 19 00:21:57 evilside pppd[27039]: Script /etc/ppp/ip-up finished (pid 
&lt;br&gt;27043), status = 0x0
&lt;br&gt;Dec 19 00:36:16 evilside pppd[27039]: rcvd [proto=0x1e77] 30 04 48 7d a5 f2 
&lt;br&gt;60 46 3b 02 7c be 51 ce 2d 06 a6 a2 3a 8a 4b e9 93 dc 75 e5 f6 c4 3c 79 f9 
&lt;br&gt;07 ...
&lt;br&gt;Dec 19 00:36:16 evilside pppd[27039]: sent [LCP ProtRej id=0x3 1e 77 30 04 
&lt;br&gt;48 7d a5 f2 60 46 3b 02 7c be 51 ce 2d 06 a6 a2 3a 8a 4b e9 93 dc 75 e5 f6 
&lt;br&gt;c4 3c 79 ...]
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: rcvd [proto=0xde3d] 57 c7 2b aa dc 1b 
&lt;br&gt;e5 f4 cd 40 19 11 66 0c 21 db 57 9a 72 72 d4 ee 3c 05 ad e9 7b ae ec ff ae 
&lt;br&gt;92 ...
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: sent [LCP ProtRej id=0x4 de 3d 57 c7 
&lt;br&gt;2b aa dc 1b e5 f4 cd 40 19 11 66 0c 21 db 57 9a 72 72 d4 ee 3c 05 ad e9 7b 
&lt;br&gt;ae ec ff ...]
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: rcvd [proto=0xd637] e5 74 ce 7d 01 67 
&lt;br&gt;89 e1 5a 31 2a c3 b1 88 a5 15 95 ed 55 6c 79 18 07 bd 82 40 72 bc 2f 63 9d 
&lt;br&gt;da ...
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: sent [LCP ProtRej id=0x5 d6 37 e5 74 
&lt;br&gt;ce 7d 01 67 89 e1 5a 31 2a c3 b1 88 a5 15 95 ed 55 6c 79 18 07 bd 82 40 72 
&lt;br&gt;bc 2f 63 ...]
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: rcvd [proto=0x4c08] 4d 2d 08 4d d9 13 
&lt;br&gt;d7 23 ec 3f 9a e7 19 f6 3a 61 97 ed 45 99 ed e0 2c fd de 75 cf 0c cc 38 55 
&lt;br&gt;9c ...
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: sent [LCP ProtRej id=0x6 4c 08 4d 2d 
&lt;br&gt;08 4d d9 13 d7 23 ec 3f 9a e7 19 f6 3a 61 97 ed 45 99 ed e0 2c fd de 75 cf 
&lt;br&gt;0c cc 38 ...]
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: rcvd [proto=0x4a97] dc a5 2e 6a 39 e0 
&lt;br&gt;0b 5a 02 74 af 3e d1 b6 f4 8f fd 48 11 ff ce 94 7a 83 4e a3 03 4f 8c 51 fb 
&lt;br&gt;78 ...
&lt;br&gt;Dec 19 00:36:17 evilside pppd[27039]: sent [LCP ProtRej id=0x7 4a 97 dc a5 
&lt;br&gt;2e 6a 39 e0 0b 5a 02 74 af 3e d1 b6 f4 8f fd 48 11 ff ce 94 7a 83 4e a3 03 
&lt;br&gt;4f 8c 51 ...]
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26853769&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Tunnel-stops-working-after-a-while%2C-LCP-ProtRej-tp26853769p26853769.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26824414</id>
	<title>Re: xp sp3 vista seven mppe problem</title>
	<published>2009-12-16T23:47:08Z</published>
	<updated>2009-12-16T23:47:08Z</updated>
	<author>
		<name>philippe gracia</name>
	</author>
	<content type="html">Le 26/11/2009 11:41, philippe gracia a écrit :
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; hi!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have the same problem described here :
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://sourceforge.net/mailarchive/message.php?msg_id=484FC86A.9020404%40wavenet.at&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sourceforge.net/mailarchive/message.php?msg_id=484FC86A.9020404%40wavenet.at&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Here is a small explanation:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; - XP3 sp3/vista/seven connect to a ppptpd-server, but cannot ping any
&lt;br&gt;&amp;gt; machine on the network, but all 98/200/xp client does.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; To make it work, You must disable encryption in the connexion properties.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; here is a cut/paste of the vista log :
&lt;br&gt;&amp;gt; Nov 26 11:24:12 mailhost pptpd[1463]: CTRL: Client xx.xx.xx.xx control
&lt;br&gt;&amp;gt; connection started
&lt;br&gt;&amp;gt; Nov 26 11:24:12 mailhost pptpd[1463]: CTRL: Starting call (launching
&lt;br&gt;&amp;gt; pppd, opening GRE)
&lt;br&gt;&amp;gt; Nov 26 11:24:12 mailhost pppd[1464]: Plugin
&lt;br&gt;&amp;gt; /usr/lib64/pptpd/pptpd-logwtmp.so loaded.
&lt;br&gt;&amp;gt; Nov 26 11:24:12 mailhost pppd[1464]: pppd 2.4.4 started by root, uid 0
&lt;br&gt;&amp;gt; Nov 26 11:24:12 mailhost pppd[1464]: Starting negotiation on /dev/pts/3
&lt;br&gt;&amp;gt; Nov 26 11:24:15 mailhost pptpd[1463]: CTRL: Ignored a SET LINK INFO
&lt;br&gt;&amp;gt; packet with real ACCMs!
&lt;br&gt;&amp;gt; Nov 26 11:24:15 mailhost pppd[1464]: Using interface ppp1
&lt;br&gt;&amp;gt; Nov 26 11:24:15 mailhost pppd[1464]: MPPE 128-bit stateful compression
&lt;br&gt;&amp;gt; enabled
&lt;br&gt;&amp;gt; Nov 26 11:24:17 mailhost pppd[1464]: found interface eth1 for proxy arp
&lt;br&gt;&amp;gt; Nov 26 11:24:17 mailhost pppd[1464]: local &amp;nbsp;IP address 10.33.1.250
&lt;br&gt;&amp;gt; Nov 26 11:24:17 mailhost pppd[1464]: remote IP address 10.33.1.75
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; my options.pptpd:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; name pptpd
&lt;br&gt;&amp;gt; lock
&lt;br&gt;&amp;gt; mtu 1400
&lt;br&gt;&amp;gt; mru 1400
&lt;br&gt;&amp;gt; proxyarp
&lt;br&gt;&amp;gt; auth
&lt;br&gt;&amp;gt; #debug
&lt;br&gt;&amp;gt; multilink
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # Strip the domain prefix from the username before authentication.
&lt;br&gt;&amp;gt; # (applies if you use pppd with chapms-strip-domain patch)
&lt;br&gt;&amp;gt; #chapms-strip-domain
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # Encryption
&lt;br&gt;&amp;gt; # (There have been multiple versions of PPP with encryption support,
&lt;br&gt;&amp;gt; # choose with of the following sections you will use.)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # BSD licensed ppp-2.4.2 upstream with MPPE only, kernel module ppp_mppe.o
&lt;br&gt;&amp;gt; # {{{
&lt;br&gt;&amp;gt; refuse-pap
&lt;br&gt;&amp;gt; refuse-chap
&lt;br&gt;&amp;gt; refuse-mschap
&lt;br&gt;&amp;gt; # Require the peer to authenticate itself using MS-CHAPv2 [Microsoft
&lt;br&gt;&amp;gt; # Challenge Handshake Authentication Protocol, Version 2] authentication.
&lt;br&gt;&amp;gt; require-mschap-v2
&lt;br&gt;&amp;gt; # Require MPPE 128-bit encryption
&lt;br&gt;&amp;gt; # (note that MPPE requires the use of MSCHAP-V2 during authentication)
&lt;br&gt;&amp;gt; #require-mppe-128
&lt;br&gt;&amp;gt; #mppe no128,no56
&lt;br&gt;&amp;gt; mppe required
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # Miscellaneous
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # Create a UUCP-style lock file for the pseudo-tty to ensure exclusive
&lt;br&gt;&amp;gt; # access.
&lt;br&gt;&amp;gt; lock
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # Disable BSD-Compress compression
&lt;br&gt;&amp;gt; nobsdcomp
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # Disable Van Jacobson compression
&lt;br&gt;&amp;gt; # (needed on some networks with Windows 9x/ME/XP clients, see posting to
&lt;br&gt;&amp;gt; # poptop-server on 14th April 2005 by Pawel Pokrywka and followups,
&lt;br&gt;&amp;gt; # &lt;a href=&quot;http://marc.theaimsgroup.com/?t=111343175400006&amp;r=1&amp;w=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://marc.theaimsgroup.com/?t=111343175400006&amp;r=1&amp;w=2&lt;/a&gt;&amp;nbsp;)
&lt;br&gt;&amp;gt; novj
&lt;br&gt;&amp;gt; novjccomp
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # turn off logging to stderr, since this may be redirected to pptpd
&lt;br&gt;&amp;gt; nologfd
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I have a strange kernel error message :
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Nov 25 15:31:14 mailhost kernel: mppe_comp_init[1]: unknown key length
&lt;br&gt;&amp;gt; Nov 25 17:04:34 mailhost kernel: mppe_decomp_init[1]: unknown key length
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; can someone help me resolve this ?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; thanks by advance
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;Hello.
&lt;br&gt;Tried to resolve by myself, but it's far away of my knowledge.
&lt;br&gt;&lt;br&gt;Really no idea ?
&lt;br&gt;&lt;br&gt;I'm feeling alone ...
&lt;br&gt;&lt;br&gt;thanks...
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26824414&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/xp-sp3-vista-seven-mppe-problem-tp26527523p26824414.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26820961</id>
	<title>Re: gre troubles</title>
	<published>2009-12-16T16:08:27Z</published>
	<updated>2009-12-16T16:08:27Z</updated>
	<author>
		<name>James Cameron-8</name>
	</author>
	<content type="html">On Wed, Dec 16, 2009 at 11:46:43AM -0800, jon heise wrote:
&lt;br&gt;&amp;gt; Dec 16 18:41:43 sjc-log1 pppd[23830]: Connect: ppp0 &amp;lt;--&amp;gt; /dev/pts/2
&lt;br&gt;&amp;gt; Dec 16 18:42:13 sjc-log1 pppd[23830]: LCP: timeout sending Config-Requests
&lt;br&gt;&amp;gt; Dec 16 18:42:13 sjc-log1 pppd[23830]: Connection terminated.
&lt;br&gt;&lt;br&gt;GRE is not getting through. &amp;nbsp;You should be able to confirm that using
&lt;br&gt;tcpdump or wireshark. &amp;nbsp;Check your routers. &amp;nbsp;Check the local system's
&lt;br&gt;iptables rules.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;James Cameron
&lt;br&gt;&lt;a href=&quot;http://quozl.linux.org.au/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://quozl.linux.org.au/&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26820961&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/gre-troubles-tp26817713p26820961.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26817713</id>
	<title>gre troubles</title>
	<published>2009-12-16T11:46:43Z</published>
	<updated>2009-12-16T11:46:43Z</updated>
	<author>
		<name>jon heise-2</name>
	</author>
	<content type="html">i'm setting up a new poptop instance and i'm running into with gre &amp;nbsp;
&lt;br&gt;getting some read error. the connection is running between an office &amp;nbsp;
&lt;br&gt;and a datacenter with acl's on the routers allowing gre through and an &amp;nbsp;
&lt;br&gt;ip traffic between the two sites through.
&lt;br&gt;&lt;br&gt;&amp;nbsp; I'm getting the following in my logs:
&lt;br&gt;&lt;br&gt;Dec 16 18:41:43 sjc-log1 pptpd[23829]: CTRL: Client *.*.*.* control &amp;nbsp;
&lt;br&gt;connection started
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pptpd[23829]: CTRL: Starting call (launching &amp;nbsp;
&lt;br&gt;pppd, opening GRE)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: pppd options in effect:
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: debug &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # (from /etc/ 
&lt;br&gt;ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: nologfd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # (from /etc/ 
&lt;br&gt;ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: dump &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# (from /etc/ 
&lt;br&gt;ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: require-mschap-v2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # &amp;nbsp;
&lt;br&gt;(from /etc/ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: refuse-pap &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;
&lt;br&gt;(from /etc/ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: refuse-chap &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # &amp;nbsp;
&lt;br&gt;(from /etc/ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: refuse-mschap &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # &amp;nbsp;
&lt;br&gt;(from /etc/ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: name pptpd &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;
&lt;br&gt;(from /etc/ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: 115200 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# (from &amp;nbsp;
&lt;br&gt;command line)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: lock &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# (from /etc/ 
&lt;br&gt;ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: local &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # (from &amp;nbsp;
&lt;br&gt;command line)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: novj &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# (from /etc/ 
&lt;br&gt;ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: novjccomp &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # (from /etc/ 
&lt;br&gt;ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: ipparam &amp;nbsp;
&lt;br&gt;64.244.66.2 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # (from command line)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: &amp;nbsp;
&lt;br&gt;192.168.30.26:192.168.30.115 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# (from command line)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: nobsdcomp &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # (from /etc/ 
&lt;br&gt;ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: require-mppe-128 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;
&lt;br&gt;(from /etc/ppp/options.pptpd)
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: pppd 2.4.4 started by root, uid 0
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: Using interface ppp0
&lt;br&gt;Dec 16 18:41:43 sjc-log1 pppd[23830]: Connect: ppp0 &amp;lt;--&amp;gt; /dev/pts/2Dec &amp;nbsp;
&lt;br&gt;16 18:42:13 sjc-log1 pppd[23830]: LCP: timeout sending Config-Requests
&lt;br&gt;Dec 16 18:42:13 sjc-log1 pppd[23830]: Connection terminated.
&lt;br&gt;Dec 16 18:42:13 sjc-log1 pppd[23830]: Modem hangupDec 16 18:42:13 sjc- 
&lt;br&gt;log1 pppd[23830]: Exit.
&lt;br&gt;Dec 16 18:42:13 sjc-log1 pptpd[23829]: GRE: read 
&lt;br&gt;(fd=6,buffer=610860,len=8196) from PTY failed: status = -1 error = &amp;nbsp;
&lt;br&gt;Input/output error, usually caused by unexpected termination of pppd, &amp;nbsp;
&lt;br&gt;check option syntax and pppd logs
&lt;br&gt;Dec 16 18:42:13 sjc-log1 pptpd[23829]: CTRL: PTY read or GRE write &amp;nbsp;
&lt;br&gt;failed (pty,gre)=(6,7)
&lt;br&gt;Dec 16 18:42:13 sjc-log1 pptpd[23829]: CTRL: Client *.*.*.* control &amp;nbsp;
&lt;br&gt;connection finished
&lt;br&gt;&lt;br&gt;&lt;br&gt;Jon Heise
&lt;br&gt;Systems Engineer
&lt;br&gt;Genius, Inc
&lt;br&gt;1400 Fashion Island Blvd, Suite 500
&lt;br&gt;650 703 8615 (C)
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;This SF.Net email is sponsored by the Verizon Developer Community
&lt;br&gt;Take advantage of Verizon's best-in-class app development support
&lt;br&gt;A streamlined, 14 day to market process makes app distribution fast and easy
&lt;br&gt;Join now and get one step closer to millions of Verizon customers
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/verizon-dev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/verizon-dev2dev&lt;/a&gt;&amp;nbsp;
&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26817713&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/gre-troubles-tp26817713p26817713.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26603036</id>
	<title>Only Partial Callingstationid</title>
	<published>2009-12-01T01:06:36Z</published>
	<updated>2009-12-01T01:06:36Z</updated>
	<author>
		<name>Neville-10</name>
	</author>
	<content type="html">Hi everyone,
&lt;br&gt;&lt;br&gt;I'm at a lost why combination of &amp;nbsp;poptop radius plugin is only passing &amp;nbsp;
&lt;br&gt;the last 4 digits of the callingstationid and in reverse order.
&lt;br&gt;&lt;br&gt;I would also like to capture MAC address, but this does not seem to be &amp;nbsp;
&lt;br&gt;possible?
&lt;br&gt;&lt;br&gt;Any ideas, pointers?
&lt;br&gt;&lt;br&gt;Kind Regards,
&lt;br&gt;&lt;br&gt;Nev
&lt;br&gt;&lt;br&gt;CentOS 5.4
&lt;br&gt;pptp 2.4.4
&lt;br&gt;Poptop 1.3.4
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Join us December 9, 2009 for the Red Hat Virtual Experience,
&lt;br&gt;a free event focused on virtualization and cloud computing. 
&lt;br&gt;Attend in-depth sessions from your desk. Your couch. Anywhere.
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/redhat-sfdev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/redhat-sfdev2dev&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26603036&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Only-Partial-Callingstationid-tp26603036p26603036.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26588415</id>
	<title>Re: poptop+freeradius</title>
	<published>2009-12-01T00:44:34Z</published>
	<updated>2009-12-01T00:44:34Z</updated>
	<author>
		<name>Oguzhan Kayhan</name>
	</author>
	<content type="html">I figured out the first problem.
&lt;br&gt;The additional dictionary packets (windows one) has the same ID with
&lt;br&gt;default dictionary file ..So freeradius was assuming a 4 digit dictionary
&lt;br&gt;parameters instead of full ip stack.
&lt;br&gt;I just changed the ID of clientipaddress and it worked.
&lt;br&gt;But still couldnt find anything about disconnect
&lt;br&gt;:(
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi, Oguzhan
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I checked my radacct table, there no problem. My radacct table like that:
&lt;br&gt;&amp;gt; +------------------+-----------------+
&lt;br&gt;&amp;gt; | callingstationid | framedipaddress |
&lt;br&gt;&amp;gt; +------------------+-----------------+
&lt;br&gt;&amp;gt; | XXX.42.176.XXX &amp;nbsp; &amp;nbsp;| 192.168.10.234 &amp;nbsp;|
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I think that you maybe not configure your radiusclient correct. Check that
&lt;br&gt;&amp;gt; if you create dictionary for pptp protocol correctly.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I couldn't help you the &amp;nbsp;2nd problem, I am also confused with radius
&lt;br&gt;&amp;gt; disconnect packet.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Tue, Nov 24, 2009 at 7:30 PM, Oguzhan Kayhan
&lt;br&gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588415&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oguzhank@...&lt;/a&gt;&amp;gt;wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;&amp;gt; I made a configuration for freeradius+pptp+mysql
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Everythings working great..Except some minor problems..
&lt;br&gt;&amp;gt;&amp;gt; Here's follows..
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I am checking radacct table on mysql to see the logs..
&lt;br&gt;&amp;gt;&amp;gt; Ok. i can see connection dates..total data trasnfers.. username
&lt;br&gt;&amp;gt;&amp;gt; etc..but..
&lt;br&gt;&amp;gt;&amp;gt; it doesnt show callingstationid for the user that connects to vpn..
&lt;br&gt;&amp;gt;&amp;gt; Just the framedIpAddress that user gets..
&lt;br&gt;&amp;gt;&amp;gt; Does anybody had such problem.. or is there any way to log the callingip
&lt;br&gt;&amp;gt;&amp;gt; addresses on mysql also???
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Second problem..
&lt;br&gt;&amp;gt;&amp;gt; Is there a way to disconnect pptp user via radius disconnect packet??
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks..
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008
&lt;br&gt;&amp;gt;&amp;gt; 30-Day
&lt;br&gt;&amp;gt;&amp;gt; trial. Simplify your report design, integration and deployment - and
&lt;br&gt;&amp;gt;&amp;gt; focus
&lt;br&gt;&amp;gt;&amp;gt; on
&lt;br&gt;&amp;gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt;&amp;gt; Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588415&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008
&lt;br&gt;&amp;gt; 30-Day
&lt;br&gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus
&lt;br&gt;&amp;gt; on
&lt;br&gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt; Crystal Reports now.
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://p.sf.net/sfu/bobj-july_______________________________________________&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july_______________________________________________&lt;/a&gt;&lt;br&gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588415&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Join us December 9, 2009 for the Red Hat Virtual Experience,
&lt;br&gt;a free event focused on virtualization and cloud computing. 
&lt;br&gt;Attend in-depth sessions from your desk. Your couch. Anywhere.
&lt;br&gt;&lt;a href=&quot;http://p.sf.net/sfu/redhat-sfdev2dev&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/redhat-sfdev2dev&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588415&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/poptop%2Bfreeradius-tp26494618p26588415.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26532944</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T09:50:04Z</published>
	<updated>2009-11-26T09:50:04Z</updated>
	<author>
		<name>Serg Smirnoff</name>
	</author>
	<content type="html">On Thu, Nov 26, 2009 at 5:30 PM, Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532944&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Thu, 26 Nov 2009, Serg Smirnoff wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; well,
&lt;br&gt;&amp;gt;&amp;gt; let's add again a two simple rules to forward like these:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; iptables -A FORWARD -s 192.168.0.0/24 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; iptables -A FORWARD -d 192.168.0.0/24 -j ACCEPT
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Those rules will be more effective if &amp;quot;inserted before&amp;quot; the &amp;quot;reject
&lt;br&gt;&amp;gt; everything&amp;quot; rule, rather than &amp;quot;appended after&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;yep, that's what I meant, I thought Fred knows about rules order.. :)
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Serg Smirnov
&lt;br&gt;email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532944&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26532944&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26532944.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26530472</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T06:46:20Z</published>
	<updated>2009-11-26T06:46:20Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">Thanks, that was it, I just removed that rule and now it works!
&lt;br&gt;-A FORWARD -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;&lt;br&gt;Should I change/remove other rules in my iptables config (below) for security?
&lt;br&gt;&lt;br&gt;# Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;*mangle
&lt;br&gt;:PREROUTING ACCEPT [92672:54733713]
&lt;br&gt;:INPUT ACCEPT [33497:3256120]
&lt;br&gt;:FORWARD ACCEPT [59175:51477593]
&lt;br&gt;:OUTPUT ACCEPT [47961:52615592]
&lt;br&gt;:POSTROUTING ACCEPT [105702:104001760]
&lt;br&gt;COMMIT
&lt;br&gt;# Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;# Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;*nat
&lt;br&gt;:PREROUTING ACCEPT [61:4397]
&lt;br&gt;:POSTROUTING ACCEPT [0:0]
&lt;br&gt;:OUTPUT ACCEPT [1:60]
&lt;br&gt;-A POSTROUTING -j MASQUERADE
&lt;br&gt;-A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
&lt;br&gt;COMMIT
&lt;br&gt;# Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;# Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;*filter
&lt;br&gt;:INPUT ACCEPT [0:0]
&lt;br&gt;:FORWARD ACCEPT [0:0]
&lt;br&gt;:OUTPUT ACCEPT [0:0]
&lt;br&gt;-A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;-A INPUT -i lo -j ACCEPT
&lt;br&gt;-A INPUT -d 127.0.0.0/8 -i ! lo -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 11431 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m state --state NEW -m tcp --dport 11430 -j ACCEPT
&lt;br&gt;-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
&lt;br&gt;-A INPUT -m limit --limit 5/min -j LOG --log-prefix &amp;quot;iptables denied:
&lt;br&gt;&amp;quot; --log-level 7
&lt;br&gt;-A INPUT -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;-A INPUT -d x.x.x.x/32 -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;-A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;-A INPUT -i ppp0 -p udp -m udp --sport 53 --dport 1024:65535 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 137 -j ACCEPT
&lt;br&gt;-A INPUT -p udp -m udp --dport 137 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 139 -j ACCEPT
&lt;br&gt;-A INPUT -p udp -m udp --dport 139 -j ACCEPT
&lt;br&gt;-A OUTPUT -j ACCEPT
&lt;br&gt;COMMIT
&lt;br&gt;# Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&lt;br&gt;&lt;br&gt;2009/11/26 Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26530472&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt; All forwarded traffic is rejected (but policy is ACCEPT).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; You need to permite forwarding in the filter table, and do
&lt;br&gt;&amp;gt; NAT/MASQUERADE in the nat table.
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26530472&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26530472.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26530258</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T06:30:17Z</published>
	<updated>2009-11-26T06:30:17Z</updated>
	<author>
		<name>Charlie Brady-13</name>
	</author>
	<content type="html">&lt;br&gt;On Thu, 26 Nov 2009, Serg Smirnoff wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; well,
&lt;br&gt;&amp;gt; let's add again a two simple rules to forward like these:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; iptables -A FORWARD -s 192.168.0.0/24 -j ACCEPT
&lt;br&gt;&amp;gt; iptables -A FORWARD -d 192.168.0.0/24 -j ACCEPT
&lt;br&gt;&lt;br&gt;Those rules will be more effective if &amp;quot;inserted before&amp;quot; the &amp;quot;reject 
&lt;br&gt;everything&amp;quot; rule, rather than &amp;quot;appended after&amp;quot;.
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26530258&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26530258.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26530251</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T06:29:10Z</published>
	<updated>2009-11-26T06:29:10Z</updated>
	<author>
		<name>Charlie Brady-13</name>
	</author>
	<content type="html">&lt;br&gt;On Thu, 26 Nov 2009, Fred wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Here you go. Note that it doesn't contain any FORWARD rules anymore,
&lt;br&gt;&lt;br&gt;That's not true.
&lt;br&gt;&lt;br&gt;&amp;gt; as all the ones I tried didn't work. But according to James' page, the
&lt;br&gt;&amp;gt; problem should be there...
&lt;br&gt;&lt;br&gt;Indeed.
&lt;br&gt;&lt;br&gt;&amp;gt; # Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt; *filter
&lt;br&gt;&amp;gt; :INPUT ACCEPT [0:0]
&lt;br&gt;&amp;gt; :FORWARD ACCEPT [0:0]
&lt;br&gt;...
&lt;br&gt;&amp;gt; -A FORWARD -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;...
&lt;br&gt;&amp;gt; COMMIT
&lt;br&gt;&amp;gt; # Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&lt;br&gt;All forwarded traffic is rejected (but policy is ACCEPT).
&lt;br&gt;&lt;br&gt;You need to permite forwarding in the filter table, and do 
&lt;br&gt;NAT/MASQUERADE in the nat table.
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26530251&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26530251.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26528989</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T04:45:47Z</published>
	<updated>2009-11-26T04:45:47Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">Thanks but that doesn't help either. Still can't ping/visit external
&lt;br&gt;websites from the client.
&lt;br&gt;&lt;br&gt;2009/11/26 Serg Smirnoff &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; well,
&lt;br&gt;&amp;gt; let's add again a two simple rules to forward like these:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; iptables -A FORWARD -s 192.168.0.0/24 -j ACCEPT
&lt;br&gt;&amp;gt; iptables -A FORWARD -d 192.168.0.0/24 -j ACCEPT
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; and after that try to reach an external target and see how the counter
&lt;br&gt;&amp;gt; will changes in &amp;quot;iptables -nL FORWARD -v&amp;quot; output.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Thu, Nov 26, 2009 at 1:43 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; Here you go. Note that it doesn't contain any FORWARD rules anymore,
&lt;br&gt;&amp;gt;&amp;gt; as all the ones I tried didn't work. But according to James' page, the
&lt;br&gt;&amp;gt;&amp;gt; problem should be there...
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; PPTP Client IP = 192.168.0.100-120
&lt;br&gt;&amp;gt;&amp;gt; PPTP Server IP = 192.168.0.1
&lt;br&gt;&amp;gt;&amp;gt; eth0 IP is a public Internet IP
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Pinging 192.168.0.1 works from the client; pinging external servers does not.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; # Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt;&amp;gt; *mangle
&lt;br&gt;&amp;gt;&amp;gt; :PREROUTING ACCEPT [92672:54733713]
&lt;br&gt;&amp;gt;&amp;gt; :INPUT ACCEPT [33497:3256120]
&lt;br&gt;&amp;gt;&amp;gt; :FORWARD ACCEPT [59175:51477593]
&lt;br&gt;&amp;gt;&amp;gt; :OUTPUT ACCEPT [47961:52615592]
&lt;br&gt;&amp;gt;&amp;gt; :POSTROUTING ACCEPT [105702:104001760]
&lt;br&gt;&amp;gt;&amp;gt; COMMIT
&lt;br&gt;&amp;gt;&amp;gt; # Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt;&amp;gt; # Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt;&amp;gt; *nat
&lt;br&gt;&amp;gt;&amp;gt; :PREROUTING ACCEPT [61:4397]
&lt;br&gt;&amp;gt;&amp;gt; :POSTROUTING ACCEPT [0:0]
&lt;br&gt;&amp;gt;&amp;gt; :OUTPUT ACCEPT [1:60]
&lt;br&gt;&amp;gt;&amp;gt; -A POSTROUTING -j MASQUERADE
&lt;br&gt;&amp;gt;&amp;gt; -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
&lt;br&gt;&amp;gt;&amp;gt; COMMIT
&lt;br&gt;&amp;gt;&amp;gt; # Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt;&amp;gt; # Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt;&amp;gt; *filter
&lt;br&gt;&amp;gt;&amp;gt; :INPUT ACCEPT [0:0]
&lt;br&gt;&amp;gt;&amp;gt; :FORWARD ACCEPT [0:0]
&lt;br&gt;&amp;gt;&amp;gt; :OUTPUT ACCEPT [0:0]
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -i lo -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -d 127.0.0.0/8 -i ! lo -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 11431 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -m state --state NEW -m tcp --dport 11430 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -m limit --limit 5/min -j LOG --log-prefix &amp;quot;iptables denied:
&lt;br&gt;&amp;gt;&amp;gt; &amp;quot; --log-level 7
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -d 194.50.91.233/32 -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -i ppp0 -p udp -m udp --sport 53 --dport 1024:65535 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 137 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p udp -m udp --dport 137 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 139 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p udp -m udp --dport 139 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A FORWARD -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;&amp;gt;&amp;gt; -A OUTPUT -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; COMMIT
&lt;br&gt;&amp;gt;&amp;gt; # Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; 2009/11/26 Serg Smirnoff &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; ok, gotcha :)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; show your current iptables configuration plz.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 1:27 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; That's 1, of course ;-)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; See my other mail, it must be some kind of iptables FORWARD rule that
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I don't have, but I can't find out which one.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 11:21 AM, Serg Smirnoff
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; huh,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; and what's the output:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; # sysctl net.ipv4.ip_forward
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 1:05 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; If it only were that easy ;-) But it doesn't work.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 10:42 AM, Serg Smirnoff
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; if the client IP from the private network you need to create the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; appropriate rules in the NAT chain, e.g.:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; iptables -A POSTROUTING -t nat -s 192.168.0.100 -j MASQUERADE
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26528989&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26528989.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26534746</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T04:00:14Z</published>
	<updated>2009-11-26T04:00:14Z</updated>
	<author>
		<name>James Cameron-8</name>
	</author>
	<content type="html">&lt;html&gt;&lt;body class=&quot;ApplePlainTextBody&quot; style=&quot;word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; &quot;&gt;On 26/11/2009, at 9:43 PM, Fred wrote:&lt;br&gt;&lt;blockquote type=&quot;cite&quot;&gt;Here you go. Note that it doesn't contain any FORWARD rules anymore,&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;as all the ones I tried didn't work. But according to James' page, the&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;problem should be there...&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;No, that's not what I said. &amp;nbsp;I said: &quot;The most common cause of failure for this test is&amp;nbsp;iptables FORWARD rules.&quot; &amp;nbsp;There are certainly other causes for failure for this test.&lt;br&gt;&lt;br&gt;&lt;blockquote type=&quot;cite&quot;&gt;*nat&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;-A POSTROUTING -j MASQUERADE&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;-A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;This looks unusual to me, because I normally MASQUERADE by selecting the output interface.&lt;br&gt;&lt;br&gt;&lt;blockquote type=&quot;cite&quot;&gt;*filter&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;:INPUT ACCEPT [0:0]&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;:FORWARD ACCEPT [0:0]&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;:OUTPUT ACCEPT [0:0]&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;...&lt;br&gt;&lt;/blockquote&gt;&lt;blockquote type=&quot;cite&quot;&gt;-A FORWARD -j REJECT --reject-with icmp-port-unreachable&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;You appear to be rejecting all forward packets in the OUTPUT rules?&lt;br&gt;&lt;br&gt;&lt;/body&gt;&lt;/html&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26534746&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26534746.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527733</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T02:59:30Z</published>
	<updated>2009-11-26T02:59:30Z</updated>
	<author>
		<name>Serg Smirnoff</name>
	</author>
	<content type="html">well,
&lt;br&gt;let's add again a two simple rules to forward like these:
&lt;br&gt;&lt;br&gt;iptables -A FORWARD -s 192.168.0.0/24 -j ACCEPT
&lt;br&gt;iptables -A FORWARD -d 192.168.0.0/24 -j ACCEPT
&lt;br&gt;&lt;br&gt;and after that try to reach an external target and see how the counter
&lt;br&gt;will changes in &amp;quot;iptables -nL FORWARD -v&amp;quot; output.
&lt;br&gt;&lt;br&gt;On Thu, Nov 26, 2009 at 1:43 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Here you go. Note that it doesn't contain any FORWARD rules anymore,
&lt;br&gt;&amp;gt; as all the ones I tried didn't work. But according to James' page, the
&lt;br&gt;&amp;gt; problem should be there...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; PPTP Client IP = 192.168.0.100-120
&lt;br&gt;&amp;gt; PPTP Server IP = 192.168.0.1
&lt;br&gt;&amp;gt; eth0 IP is a public Internet IP
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Pinging 192.168.0.1 works from the client; pinging external servers does not.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt; *mangle
&lt;br&gt;&amp;gt; :PREROUTING ACCEPT [92672:54733713]
&lt;br&gt;&amp;gt; :INPUT ACCEPT [33497:3256120]
&lt;br&gt;&amp;gt; :FORWARD ACCEPT [59175:51477593]
&lt;br&gt;&amp;gt; :OUTPUT ACCEPT [47961:52615592]
&lt;br&gt;&amp;gt; :POSTROUTING ACCEPT [105702:104001760]
&lt;br&gt;&amp;gt; COMMIT
&lt;br&gt;&amp;gt; # Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt; # Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt; *nat
&lt;br&gt;&amp;gt; :PREROUTING ACCEPT [61:4397]
&lt;br&gt;&amp;gt; :POSTROUTING ACCEPT [0:0]
&lt;br&gt;&amp;gt; :OUTPUT ACCEPT [1:60]
&lt;br&gt;&amp;gt; -A POSTROUTING -j MASQUERADE
&lt;br&gt;&amp;gt; -A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
&lt;br&gt;&amp;gt; COMMIT
&lt;br&gt;&amp;gt; # Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt; # Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt; *filter
&lt;br&gt;&amp;gt; :INPUT ACCEPT [0:0]
&lt;br&gt;&amp;gt; :FORWARD ACCEPT [0:0]
&lt;br&gt;&amp;gt; :OUTPUT ACCEPT [0:0]
&lt;br&gt;&amp;gt; -A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -i lo -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -d 127.0.0.0/8 -i ! lo -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;&amp;gt; -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 11431 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -m state --state NEW -m tcp --dport 11430 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -m limit --limit 5/min -j LOG --log-prefix &amp;quot;iptables denied:
&lt;br&gt;&amp;gt; &amp;quot; --log-level 7
&lt;br&gt;&amp;gt; -A INPUT -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;&amp;gt; -A INPUT -d 194.50.91.233/32 -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -i ppp0 -p udp -m udp --sport 53 --dport 1024:65535 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 137 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p udp -m udp --dport 137 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -m tcp --dport 139 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p udp -m udp --dport 139 -j ACCEPT
&lt;br&gt;&amp;gt; -A FORWARD -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;&amp;gt; -A OUTPUT -j ACCEPT
&lt;br&gt;&amp;gt; COMMIT
&lt;br&gt;&amp;gt; # Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 2009/11/26 Serg Smirnoff &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt;&amp;gt; ok, gotcha :)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; show your current iptables configuration plz.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 1:27 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; That's 1, of course ;-)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; See my other mail, it must be some kind of iptables FORWARD rule that
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I don't have, but I can't find out which one.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 11:21 AM, Serg Smirnoff
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; huh,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; and what's the output:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; # sysctl net.ipv4.ip_forward
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 1:05 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; If it only were that easy ;-) But it doesn't work.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 10:42 AM, Serg Smirnoff
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; if the client IP from the private network you need to create the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; appropriate rules in the NAT chain, e.g.:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; iptables -A POSTROUTING -t nat -s 192.168.0.100 -j MASQUERADE
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Serg Smirnov
&lt;br&gt;email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527733&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26527733.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527548</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T02:43:02Z</published>
	<updated>2009-11-26T02:43:02Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">Here you go. Note that it doesn't contain any FORWARD rules anymore,
&lt;br&gt;as all the ones I tried didn't work. But according to James' page, the
&lt;br&gt;problem should be there...
&lt;br&gt;&lt;br&gt;PPTP Client IP = 192.168.0.100-120
&lt;br&gt;PPTP Server IP = 192.168.0.1
&lt;br&gt;eth0 IP is a public Internet IP
&lt;br&gt;&lt;br&gt;Pinging 192.168.0.1 works from the client; pinging external servers does not.
&lt;br&gt;&lt;br&gt;# Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;*mangle
&lt;br&gt;:PREROUTING ACCEPT [92672:54733713]
&lt;br&gt;:INPUT ACCEPT [33497:3256120]
&lt;br&gt;:FORWARD ACCEPT [59175:51477593]
&lt;br&gt;:OUTPUT ACCEPT [47961:52615592]
&lt;br&gt;:POSTROUTING ACCEPT [105702:104001760]
&lt;br&gt;COMMIT
&lt;br&gt;# Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;# Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;*nat
&lt;br&gt;:PREROUTING ACCEPT [61:4397]
&lt;br&gt;:POSTROUTING ACCEPT [0:0]
&lt;br&gt;:OUTPUT ACCEPT [1:60]
&lt;br&gt;-A POSTROUTING -j MASQUERADE
&lt;br&gt;-A POSTROUTING -s 192.168.0.0/24 -j MASQUERADE
&lt;br&gt;COMMIT
&lt;br&gt;# Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;# Generated by iptables-save v1.4.2 on Thu Nov 26 11:38:12 2009
&lt;br&gt;*filter
&lt;br&gt;:INPUT ACCEPT [0:0]
&lt;br&gt;:FORWARD ACCEPT [0:0]
&lt;br&gt;:OUTPUT ACCEPT [0:0]
&lt;br&gt;-A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;-A INPUT -i lo -j ACCEPT
&lt;br&gt;-A INPUT -d 127.0.0.0/8 -i ! lo -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 443 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 11431 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m state --state NEW -m tcp --dport 11430 -j ACCEPT
&lt;br&gt;-A INPUT -p icmp -m icmp --icmp-type 8 -j ACCEPT
&lt;br&gt;-A INPUT -m limit --limit 5/min -j LOG --log-prefix &amp;quot;iptables denied:
&lt;br&gt;&amp;quot; --log-level 7
&lt;br&gt;-A INPUT -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;-A INPUT -d 194.50.91.233/32 -p tcp -m tcp --dport 1723 -j ACCEPT
&lt;br&gt;-A INPUT -i ppp0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
&lt;br&gt;-A INPUT -i ppp0 -p udp -m udp --sport 53 --dport 1024:65535 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 137 -j ACCEPT
&lt;br&gt;-A INPUT -p udp -m udp --dport 137 -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -m tcp --dport 139 -j ACCEPT
&lt;br&gt;-A INPUT -p udp -m udp --dport 139 -j ACCEPT
&lt;br&gt;-A FORWARD -j REJECT --reject-with icmp-port-unreachable
&lt;br&gt;-A OUTPUT -j ACCEPT
&lt;br&gt;COMMIT
&lt;br&gt;# Completed on Thu Nov 26 11:38:12 2009
&lt;br&gt;&lt;br&gt;&lt;br&gt;2009/11/26 Serg Smirnoff &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; ok, gotcha :)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; show your current iptables configuration plz.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Thu, Nov 26, 2009 at 1:27 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; That's 1, of course ;-)
&lt;br&gt;&amp;gt;&amp;gt; See my other mail, it must be some kind of iptables FORWARD rule that
&lt;br&gt;&amp;gt;&amp;gt; I don't have, but I can't find out which one.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 11:21 AM, Serg Smirnoff
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; huh,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; and what's the output:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; # sysctl net.ipv4.ip_forward
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 1:05 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; If it only were that easy ;-) But it doesn't work.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 10:42 AM, Serg Smirnoff
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; if the client IP from the private network you need to create the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; appropriate rules in the NAT chain, e.g.:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; iptables -A POSTROUTING -t nat -s 192.168.0.100 -j MASQUERADE
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527548&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26527548.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527523</id>
	<title>xp sp3 vista seven mppe problem</title>
	<published>2009-11-26T02:41:05Z</published>
	<updated>2009-11-26T02:41:05Z</updated>
	<author>
		<name>philippe gracia</name>
	</author>
	<content type="html">hi!
&lt;br&gt;&lt;br&gt;I have the same problem described here :
&lt;br&gt;&lt;a href=&quot;http://sourceforge.net/mailarchive/message.php?msg_id=484FC86A.9020404%40wavenet.at&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sourceforge.net/mailarchive/message.php?msg_id=484FC86A.9020404%40wavenet.at&lt;/a&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Here is a small explanation:
&lt;br&gt;&lt;br&gt;- XP3 sp3/vista/seven connect to a ppptpd-server, but cannot ping any 
&lt;br&gt;machine on the network, but all 98/200/xp client does.
&lt;br&gt;&lt;br&gt;To make it work, You must disable encryption in the connexion properties.
&lt;br&gt;&lt;br&gt;here is a cut/paste of the vista log :
&lt;br&gt;Nov 26 11:24:12 mailhost pptpd[1463]: CTRL: Client xx.xx.xx.xx control 
&lt;br&gt;connection started
&lt;br&gt;Nov 26 11:24:12 mailhost pptpd[1463]: CTRL: Starting call (launching 
&lt;br&gt;pppd, opening GRE)
&lt;br&gt;Nov 26 11:24:12 mailhost pppd[1464]: Plugin 
&lt;br&gt;/usr/lib64/pptpd/pptpd-logwtmp.so loaded.
&lt;br&gt;Nov 26 11:24:12 mailhost pppd[1464]: pppd 2.4.4 started by root, uid 0
&lt;br&gt;Nov 26 11:24:12 mailhost pppd[1464]: Starting negotiation on /dev/pts/3
&lt;br&gt;Nov 26 11:24:15 mailhost pptpd[1463]: CTRL: Ignored a SET LINK INFO 
&lt;br&gt;packet with real ACCMs!
&lt;br&gt;Nov 26 11:24:15 mailhost pppd[1464]: Using interface ppp1
&lt;br&gt;Nov 26 11:24:15 mailhost pppd[1464]: MPPE 128-bit stateful compression 
&lt;br&gt;enabled
&lt;br&gt;Nov 26 11:24:17 mailhost pppd[1464]: found interface eth1 for proxy arp
&lt;br&gt;Nov 26 11:24:17 mailhost pppd[1464]: local &amp;nbsp;IP address 10.33.1.250
&lt;br&gt;Nov 26 11:24:17 mailhost pppd[1464]: remote IP address 10.33.1.75
&lt;br&gt;&lt;br&gt;&lt;br&gt;my options.pptpd:
&lt;br&gt;&lt;br&gt;name pptpd
&lt;br&gt;lock
&lt;br&gt;mtu 1400
&lt;br&gt;mru 1400
&lt;br&gt;proxyarp
&lt;br&gt;auth
&lt;br&gt;#debug
&lt;br&gt;multilink
&lt;br&gt;&lt;br&gt;# Strip the domain prefix from the username before authentication.
&lt;br&gt;# (applies if you use pppd with chapms-strip-domain patch)
&lt;br&gt;#chapms-strip-domain
&lt;br&gt;&lt;br&gt;&lt;br&gt;# Encryption
&lt;br&gt;# (There have been multiple versions of PPP with encryption support,
&lt;br&gt;# choose with of the following sections you will use.)
&lt;br&gt;&lt;br&gt;&lt;br&gt;# BSD licensed ppp-2.4.2 upstream with MPPE only, kernel module ppp_mppe.o
&lt;br&gt;# {{{
&lt;br&gt;refuse-pap
&lt;br&gt;refuse-chap
&lt;br&gt;refuse-mschap
&lt;br&gt;# Require the peer to authenticate itself using MS-CHAPv2 [Microsoft
&lt;br&gt;# Challenge Handshake Authentication Protocol, Version 2] authentication.
&lt;br&gt;require-mschap-v2
&lt;br&gt;# Require MPPE 128-bit encryption
&lt;br&gt;# (note that MPPE requires the use of MSCHAP-V2 during authentication)
&lt;br&gt;#require-mppe-128
&lt;br&gt;#mppe no128,no56
&lt;br&gt;mppe required
&lt;br&gt;&lt;br&gt;# Miscellaneous
&lt;br&gt;&lt;br&gt;# Create a UUCP-style lock file for the pseudo-tty to ensure exclusive
&lt;br&gt;# access.
&lt;br&gt;lock
&lt;br&gt;&lt;br&gt;# Disable BSD-Compress compression
&lt;br&gt;nobsdcomp
&lt;br&gt;&lt;br&gt;# Disable Van Jacobson compression
&lt;br&gt;# (needed on some networks with Windows 9x/ME/XP clients, see posting to
&lt;br&gt;# poptop-server on 14th April 2005 by Pawel Pokrywka and followups,
&lt;br&gt;# &lt;a href=&quot;http://marc.theaimsgroup.com/?t=111343175400006&amp;r=1&amp;w=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://marc.theaimsgroup.com/?t=111343175400006&amp;r=1&amp;w=2&lt;/a&gt;&amp;nbsp;)
&lt;br&gt;novj
&lt;br&gt;novjccomp
&lt;br&gt;&lt;br&gt;# turn off logging to stderr, since this may be redirected to pptpd
&lt;br&gt;nologfd
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;I have a strange kernel error message :
&lt;br&gt;&lt;br&gt;Nov 25 15:31:14 mailhost kernel: mppe_comp_init[1]: unknown key length
&lt;br&gt;Nov 25 17:04:34 mailhost kernel: mppe_decomp_init[1]: unknown key length
&lt;br&gt;&lt;br&gt;&lt;br&gt;can someone help me resolve this ?
&lt;br&gt;&lt;br&gt;thanks by advance
&lt;br&gt;&lt;br&gt;&lt;br&gt;----
&lt;br&gt;please excuse my poor english as i'm french ! ;)
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527523&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/xp-sp3-vista-seven-mppe-problem-tp26527523p26527523.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527351</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T02:27:41Z</published>
	<updated>2009-11-26T02:27:41Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">That's 1, of course ;-)
&lt;br&gt;See my other mail, it must be some kind of iptables FORWARD rule that
&lt;br&gt;I don't have, but I can't find out which one.
&lt;br&gt;&lt;br&gt;On Thu, Nov 26, 2009 at 11:21 AM, Serg Smirnoff
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527351&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; huh,
&lt;br&gt;&amp;gt; and what's the output:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # sysctl net.ipv4.ip_forward
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Thu, Nov 26, 2009 at 1:05 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527351&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; If it only were that easy ;-) But it doesn't work.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Thu, Nov 26, 2009 at 10:42 AM, Serg Smirnoff
&lt;br&gt;&amp;gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527351&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; if the client IP from the private network you need to create the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; appropriate rules in the NAT chain, e.g.:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; iptables -A POSTROUTING -t nat -s 192.168.0.100 -j MASQUERADE
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527351&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Serg Smirnov
&lt;br&gt;&amp;gt; email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527351&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527351&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26527351.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527264</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T02:21:59Z</published>
	<updated>2009-11-26T02:21:59Z</updated>
	<author>
		<name>Serg Smirnoff</name>
	</author>
	<content type="html">huh,
&lt;br&gt;and what's the output:
&lt;br&gt;&lt;br&gt;# sysctl net.ipv4.ip_forward
&lt;br&gt;&lt;br&gt;On Thu, Nov 26, 2009 at 1:05 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527264&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; If it only were that easy ;-) But it doesn't work.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Thu, Nov 26, 2009 at 10:42 AM, Serg Smirnoff
&lt;br&gt;&amp;gt; &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527264&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; if the client IP from the private network you need to create the
&lt;br&gt;&amp;gt;&amp;gt; appropriate rules in the NAT chain, e.g.:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; iptables -A POSTROUTING -t nat -s 192.168.0.100 -j MASQUERADE
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527264&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Serg Smirnov
&lt;br&gt;email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527264&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527264&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26527264.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527076</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T02:05:27Z</published>
	<updated>2009-11-26T02:05:27Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">If it only were that easy ;-) But it doesn't work.
&lt;br&gt;&lt;br&gt;On Thu, Nov 26, 2009 at 10:42 AM, Serg Smirnoff
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527076&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sergey.a.smirnov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; if the client IP from the private network you need to create the
&lt;br&gt;&amp;gt; appropriate rules in the NAT chain, e.g.:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; iptables -A POSTROUTING -t nat -s 192.168.0.100 -j MASQUERADE
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527076&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26527076.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527077</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T02:04:48Z</published>
	<updated>2009-11-26T02:04:48Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">James, this is a great page! I did testing and it fails at step 4:
&lt;br&gt;tcpdump doesn't show anything at this stage.
&lt;br&gt;tcpdump -n -i eth0 icmp and dst host 209.85.227.103
&lt;br&gt;(using the IP of Google as a test)
&lt;br&gt;Steps 1-3 all pass.
&lt;br&gt;&lt;br&gt;How can I solve this? I am using these variables:
&lt;br&gt;Client Name : client
&lt;br&gt;Client Tunnel Network Interface : 	ppp0
&lt;br&gt;Client Tunnel Network Interface Address : 	192.168.0.100
&lt;br&gt;Server Name : 	server
&lt;br&gt;Server Tunnel Network Interface : ppp0
&lt;br&gt;Server Tunnel Network Interface Address : 	192.168.0.1
&lt;br&gt;Server External Network Interface : 	eth0
&lt;br&gt;Server External Network Interface Address : (server's public IP)
&lt;br&gt;Target External Network Interface Address : 209.85.227.103 (google test IP)
&lt;br&gt;&lt;br&gt;Thanks for your help!	
&lt;br&gt;&lt;br&gt;On Wed, Nov 25, 2009 at 11:30 PM, James Cameron &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527077&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;quozl@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Familiar.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Read what I wrote about it before:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://poptop.sourceforge.net/dox/diagnose-forwarding.phtml&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://poptop.sourceforge.net/dox/diagnose-forwarding.phtml&lt;/a&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527077&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26527077.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26526803</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-26T01:42:58Z</published>
	<updated>2009-11-26T01:42:58Z</updated>
	<author>
		<name>Serg Smirnoff</name>
	</author>
	<content type="html">Greetings,
&lt;br&gt;&lt;br&gt;if the client IP from the private network you need to create the
&lt;br&gt;appropriate rules in the NAT chain, e.g.:
&lt;br&gt;&lt;br&gt;iptables -A POSTROUTING -t nat -s 192.168.0.100 -j MASQUERADE
&lt;br&gt;&lt;br&gt;On Wed, Nov 25, 2009 at 12:40 PM, Fred &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I have done more testing and added rules to allow ppp0 for ports 67-69
&lt;br&gt;&amp;gt; and 137-139, and my error disappears. However, it still doesn't work.
&lt;br&gt;&amp;gt; My syslog show exactly the same errors when I switch off iptables, and
&lt;br&gt;&amp;gt; then everything works fine. When I switch on iptables again, I can't
&lt;br&gt;&amp;gt; surf using the PPTP, but no other errors are logged in syslog. So I
&lt;br&gt;&amp;gt; don't know what to do now...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Pinging the pptp server (192.168.0.1) from the Windows client works
&lt;br&gt;&amp;gt; fine even with iptables on, but I cannot ping an internet host (though
&lt;br&gt;&amp;gt; it resolves fine using the DNS server of the PPTP server), giving me
&lt;br&gt;&amp;gt; destination port unreachable.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any help would be greatly appreciated as I have now spent hours trying
&lt;br&gt;&amp;gt; to resolve it.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This is a sample log
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Nov 25 10:21:40 bevc pptpd[22917]: CTRL: Client x.x.x.x control
&lt;br&gt;&amp;gt; connection started
&lt;br&gt;&amp;gt; Nov 25 10:21:40 bevc pptpd[22917]: CTRL: Starting call (launching
&lt;br&gt;&amp;gt; pppd, opening GRE)
&lt;br&gt;&amp;gt; Nov 25 10:21:40 bevc pppd[22918]: Plugin /usr/lib/pptpd/pptpd-logwtmp.so loaded.
&lt;br&gt;&amp;gt; Nov 25 10:21:40 bevc pppd[22918]: pppd 2.4.4 started by root, uid 0
&lt;br&gt;&amp;gt; Nov 25 10:21:40 bevc pppd[22918]: Using interface ppp0
&lt;br&gt;&amp;gt; Nov 25 10:21:40 bevc pppd[22918]: Connect: ppp0 &amp;lt;--&amp;gt; /dev/pts/1
&lt;br&gt;&amp;gt; Nov 25 10:21:40 bevc pptpd[22917]: GRE: Bad checksum from pppd. (THIS
&lt;br&gt;&amp;gt; ERROR SEEMS &amp;quot;NORMAL&amp;quot;)
&lt;br&gt;&amp;gt; Nov 25 10:21:43 bevc pptpd[22917]: CTRL: Ignored a SET LINK INFO
&lt;br&gt;&amp;gt; packet with real ACCMs! (THIS ERROR SEEMS &amp;quot;NORMAL&amp;quot;)
&lt;br&gt;&amp;gt; Nov 25 10:21:44 bevc pppd[22918]: Cannot determine ethernet address
&lt;br&gt;&amp;gt; for proxy ARP
&lt;br&gt;&amp;gt; Nov 25 10:21:44 bevc pppd[22918]: local  IP address 192.168.0.1
&lt;br&gt;&amp;gt; Nov 25 10:21:44 bevc pppd[22918]: remote IP address 192.168.0.100
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pppd[22918]: LCP terminated by peer
&lt;br&gt;&amp;gt; (&amp;gt;M-Q^OB^@&amp;lt;M-Mt^@^@^@^@)
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pppd[22918]: Connect time 0.1 minutes.
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pppd[22918]: Sent 1214 bytes, received 2387 bytes.
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pptpd[22917]: CTRL: Reaping child PPP[22918]
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pppd[22918]: Modem hangup
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pppd[22918]: Connection terminated.
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pppd[22918]: Exit.
&lt;br&gt;&amp;gt; Nov 25 10:21:50 bevc pptpd[22917]: CTRL: Client x.x.x.x control
&lt;br&gt;&amp;gt; connection finished
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Tue, Nov 24, 2009 at 7:38 PM, Edvin Seferovic | Kolpinghaus
&lt;br&gt;&amp;gt; St.Polten &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;edvin.seferovic@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; you should allow traffic to flow from and to the PPP interface that has been
&lt;br&gt;&amp;gt;&amp;gt; created when the VPN connection got set up.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ipt -A INPUT -i ppp+ -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; ipt -A OUTPUT -o ppp+ -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; ipt -A FORWARD -i ppp+ -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; ipt -A FORWARD -o ppp+ -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; There are also scripts which are started when the interface is brought up or
&lt;br&gt;&amp;gt;&amp;gt; down. /etc/ppp/ip-up ... you can enter some specific rules there.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt;&amp;gt; E:S
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt;&amp;gt; From: Fred [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;]
&lt;br&gt;&amp;gt;&amp;gt; Sent: Dienstag, 24. November 2009 19:21
&lt;br&gt;&amp;gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: Re: [Poptop-server] PPTP and iptables problem
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Well my problem is that I can't connect to any websites through the
&lt;br&gt;&amp;gt;&amp;gt; VPN. They just time out. When I clear all iptables rules, it works
&lt;br&gt;&amp;gt;&amp;gt; fine.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; PPTP on the server has a WAN IP (eth0) and gives a LAN IP to the PPTP
&lt;br&gt;&amp;gt;&amp;gt; client (192.168.0.100) when connecting to the server.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; So it must be some iptables rule, but I cannot find it at all...
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Tue, Nov 24, 2009 at 6:13 PM, Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I am happily running PPTP/Poptop on Debian 5.0 as a server, connecting
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; with a Windows VPN client. It works fine if iptables is disabled, but
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; when I enable it, I get problems.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; What problems do you have? All we know is that you see some iptables
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 'denied' messages.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I have these rules:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -A INPUT -p tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -A INPUT -p gre -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; -A INPUT -p tcp -s 0/0 -d (server IP) --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This lets me connect to the server, but when I try to send traffic
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; over the link (eg visiting a website), syslog shows me this error
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Nov 24 17:56:23 bevc kernel: [3906338.922822] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=1 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Nov 24 17:56:26 bevc kernel: [3906341.923159] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=13 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; That appears to be your peer sending DHCP client discovery messages.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; ppp0 is the pptp connection on the server. (default) and pptp
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; allocates 192.168.0.100 to the client
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Any idea how to solve this? I have spent hours trying to come up with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; the correct iptables rule, but can't find it.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ----------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus
&lt;br&gt;&amp;gt;&amp;gt; on
&lt;br&gt;&amp;gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Serg Smirnov
&lt;br&gt;email/xmpp: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Sergey.A.Smirnov@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526803&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26526803.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26524618</id>
	<title>Re: poptop+freeradius</title>
	<published>2009-11-25T21:42:10Z</published>
	<updated>2009-11-25T21:42:10Z</updated>
	<author>
		<name>maodan</name>
	</author>
	<content type="html">Hi, Oguzhan&lt;br&gt;&lt;br&gt;I checked my radacct table, there no problem. My radacct table like that:&lt;br&gt;+------------------+-----------------+&lt;br&gt;| callingstationid | framedipaddress |&lt;br&gt;+------------------+-----------------+&lt;br&gt;
| XXX.42.176.XXX    | 192.168.10.234  | &lt;br&gt;&lt;br&gt;I think that you maybe not configure your radiusclient correct. Check that if you create dictionary for pptp protocol correctly.&lt;br&gt;&lt;br&gt;I couldn&amp;#39;t help you the  2nd problem, I am also confused with radius disconnect packet.&lt;br&gt;
&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Tue, Nov 24, 2009 at 7:30 PM, Oguzhan Kayhan &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26524618&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oguzhank@...&lt;/a&gt;&amp;gt;&lt;/span&gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Hello,&lt;br&gt;
I made a configuration for freeradius+pptp+mysql&lt;br&gt;
&lt;br&gt;
Everythings working great..Except some minor problems..&lt;br&gt;
Here&amp;#39;s follows..&lt;br&gt;
&lt;br&gt;
I am checking radacct table on mysql to see the logs..&lt;br&gt;
Ok. i can see connection dates..total data trasnfers.. username etc..but..&lt;br&gt;
it doesnt show callingstationid for the user that connects to vpn..&lt;br&gt;
Just the framedIpAddress that user gets..&lt;br&gt;
Does anybody had such problem.. or is there any way to log the callingip&lt;br&gt;
addresses on mysql also???&lt;br&gt;
&lt;br&gt;
Second problem..&lt;br&gt;
Is there a way to disconnect pptp user via radius disconnect packet??&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
Thanks..&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
------------------------------------------------------------------------------&lt;br&gt;
Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day&lt;br&gt;
trial. Simplify your report design, integration and deployment - and focus on&lt;br&gt;
what you do best, core application coding. Discover what&amp;#39;s new with&lt;br&gt;
Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;
_______________________________________________&lt;br&gt;
Poptop-server mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26524618&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;br /&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26524618&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/poptop%2Bfreeradius-tp26494618p26524618.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26521461</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-25T14:30:42Z</published>
	<updated>2009-11-25T14:30:42Z</updated>
	<author>
		<name>James Cameron-8</name>
	</author>
	<content type="html">On 25/11/2009, at 8:40 PM, Fred wrote:
&lt;br&gt;&amp;gt; I have done more testing and added rules to allow ppp0 for ports 67-69
&lt;br&gt;&amp;gt; and 137-139, and my error disappears. However, it still doesn't work.
&lt;br&gt;&amp;gt; My syslog show exactly the same errors when I switch off iptables, and
&lt;br&gt;&amp;gt; then everything works fine. When I switch on iptables again, I can't
&lt;br&gt;&amp;gt; surf using the PPTP, but no other errors are logged in syslog. So I
&lt;br&gt;&amp;gt; don't know what to do now...
&lt;br&gt;&lt;br&gt;Sounds like forwarding problems.
&lt;br&gt;&lt;br&gt;&amp;gt; Pinging the pptp server (192.168.0.1) from the Windows client works
&lt;br&gt;&amp;gt; fine even with iptables on, but I cannot ping an internet host (though
&lt;br&gt;&amp;gt; it resolves fine using the DNS server of the PPTP server), giving me
&lt;br&gt;&amp;gt; destination port unreachable.
&lt;br&gt;&lt;br&gt;Sounds very like forwarding problem.
&lt;br&gt;&lt;br&gt;Familiar.
&lt;br&gt;&lt;br&gt;Read what I wrote about it before:
&lt;br&gt;&lt;a href=&quot;http://poptop.sourceforge.net/dox/diagnose-forwarding.phtml&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://poptop.sourceforge.net/dox/diagnose-forwarding.phtml&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26521461&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26521461.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26509907</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-25T01:40:55Z</published>
	<updated>2009-11-25T01:40:55Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">I have done more testing and added rules to allow ppp0 for ports 67-69
&lt;br&gt;and 137-139, and my error disappears. However, it still doesn't work.
&lt;br&gt;My syslog show exactly the same errors when I switch off iptables, and
&lt;br&gt;then everything works fine. When I switch on iptables again, I can't
&lt;br&gt;surf using the PPTP, but no other errors are logged in syslog. So I
&lt;br&gt;don't know what to do now...
&lt;br&gt;&lt;br&gt;Pinging the pptp server (192.168.0.1) from the Windows client works
&lt;br&gt;fine even with iptables on, but I cannot ping an internet host (though
&lt;br&gt;it resolves fine using the DNS server of the PPTP server), giving me
&lt;br&gt;destination port unreachable.
&lt;br&gt;&lt;br&gt;Any help would be greatly appreciated as I have now spent hours trying
&lt;br&gt;to resolve it.
&lt;br&gt;&lt;br&gt;This is a sample log
&lt;br&gt;&lt;br&gt;Nov 25 10:21:40 bevc pptpd[22917]: CTRL: Client x.x.x.x control
&lt;br&gt;connection started
&lt;br&gt;Nov 25 10:21:40 bevc pptpd[22917]: CTRL: Starting call (launching
&lt;br&gt;pppd, opening GRE)
&lt;br&gt;Nov 25 10:21:40 bevc pppd[22918]: Plugin /usr/lib/pptpd/pptpd-logwtmp.so loaded.
&lt;br&gt;Nov 25 10:21:40 bevc pppd[22918]: pppd 2.4.4 started by root, uid 0
&lt;br&gt;Nov 25 10:21:40 bevc pppd[22918]: Using interface ppp0
&lt;br&gt;Nov 25 10:21:40 bevc pppd[22918]: Connect: ppp0 &amp;lt;--&amp;gt; /dev/pts/1
&lt;br&gt;Nov 25 10:21:40 bevc pptpd[22917]: GRE: Bad checksum from pppd. (THIS
&lt;br&gt;ERROR SEEMS &amp;quot;NORMAL&amp;quot;)
&lt;br&gt;Nov 25 10:21:43 bevc pptpd[22917]: CTRL: Ignored a SET LINK INFO
&lt;br&gt;packet with real ACCMs! (THIS ERROR SEEMS &amp;quot;NORMAL&amp;quot;)
&lt;br&gt;Nov 25 10:21:44 bevc pppd[22918]: Cannot determine ethernet address
&lt;br&gt;for proxy ARP
&lt;br&gt;Nov 25 10:21:44 bevc pppd[22918]: local &amp;nbsp;IP address 192.168.0.1
&lt;br&gt;Nov 25 10:21:44 bevc pppd[22918]: remote IP address 192.168.0.100
&lt;br&gt;Nov 25 10:21:50 bevc pppd[22918]: LCP terminated by peer
&lt;br&gt;(&amp;gt;M-Q^OB^@&amp;lt;M-Mt^@^@^@^@)
&lt;br&gt;Nov 25 10:21:50 bevc pppd[22918]: Connect time 0.1 minutes.
&lt;br&gt;Nov 25 10:21:50 bevc pppd[22918]: Sent 1214 bytes, received 2387 bytes.
&lt;br&gt;Nov 25 10:21:50 bevc pptpd[22917]: CTRL: Reaping child PPP[22918]
&lt;br&gt;Nov 25 10:21:50 bevc pppd[22918]: Modem hangup
&lt;br&gt;Nov 25 10:21:50 bevc pppd[22918]: Connection terminated.
&lt;br&gt;Nov 25 10:21:50 bevc pppd[22918]: Exit.
&lt;br&gt;Nov 25 10:21:50 bevc pptpd[22917]: CTRL: Client x.x.x.x control
&lt;br&gt;connection finished
&lt;br&gt;&lt;br&gt;On Tue, Nov 24, 2009 at 7:38 PM, Edvin Seferovic | Kolpinghaus
&lt;br&gt;St.Polten &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26509907&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;edvin.seferovic@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; you should allow traffic to flow from and to the PPP interface that has been
&lt;br&gt;&amp;gt; created when the VPN connection got set up.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ipt -A INPUT -i ppp+ -j ACCEPT
&lt;br&gt;&amp;gt; ipt -A OUTPUT -o ppp+ -j ACCEPT
&lt;br&gt;&amp;gt; ipt -A FORWARD -i ppp+ -j ACCEPT
&lt;br&gt;&amp;gt; ipt -A FORWARD -o ppp+ -j ACCEPT
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; There are also scripts which are started when the interface is brought up or
&lt;br&gt;&amp;gt; down. /etc/ppp/ip-up ... you can enter some specific rules there.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Regards,
&lt;br&gt;&amp;gt; E:S
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Fred [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26509907&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Sent: Dienstag, 24. November 2009 19:21
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26509907&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Re: [Poptop-server] PPTP and iptables problem
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Well my problem is that I can't connect to any websites through the
&lt;br&gt;&amp;gt; VPN. They just time out. When I clear all iptables rules, it works
&lt;br&gt;&amp;gt; fine.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; PPTP on the server has a WAN IP (eth0) and gives a LAN IP to the PPTP
&lt;br&gt;&amp;gt; client (192.168.0.100) when connecting to the server.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; So it must be some iptables rule, but I cannot find it at all...
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Tue, Nov 24, 2009 at 6:13 PM, Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26509907&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I am happily running PPTP/Poptop on Debian 5.0 as a server, connecting
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; with a Windows VPN client. It works fine if iptables is disabled, but
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; when I enable it, I get problems.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; What problems do you have? All we know is that you see some iptables
&lt;br&gt;&amp;gt;&amp;gt; 'denied' messages.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I have these rules:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; -A INPUT -p tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; -A INPUT -p gre -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; -A INPUT -p tcp -s 0/0 -d (server IP) --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; This lets me connect to the server, but when I try to send traffic
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; over the link (eg visiting a website), syslog shows me this error
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Nov 24 17:56:23 bevc kernel: [3906338.922822] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=1 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Nov 24 17:56:26 bevc kernel: [3906341.923159] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=13 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; That appears to be your peer sending DHCP client discovery messages.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; ppp0 is the pptp connection on the server. (default) and pptp
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; allocates 192.168.0.100 to the client
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Any idea how to solve this? I have spent hours trying to come up with
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; the correct iptables rule, but can't find it.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ----------------------------------------------------------------------------
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus
&lt;br&gt;&amp;gt; on
&lt;br&gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26509907&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------------
&lt;br&gt;&amp;gt; Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day
&lt;br&gt;&amp;gt; trial. Simplify your report design, integration and deployment - and focus on
&lt;br&gt;&amp;gt; what you do best, core application coding. Discover what's new with
&lt;br&gt;&amp;gt; Crystal Reports now.  &lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Poptop-server mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26509907&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26509907&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26509907.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26501592</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-24T10:38:54Z</published>
	<updated>2009-11-24T10:38:54Z</updated>
	<author>
		<name>Edvin Seferovic</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;you should allow traffic to flow from and to the PPP interface that has been
&lt;br&gt;created when the VPN connection got set up.
&lt;br&gt;&lt;br&gt;ipt -A INPUT -i ppp+ -j ACCEPT
&lt;br&gt;ipt -A OUTPUT -o ppp+ -j ACCEPT
&lt;br&gt;ipt -A FORWARD -i ppp+ -j ACCEPT
&lt;br&gt;ipt -A FORWARD -o ppp+ -j ACCEPT
&lt;br&gt;&lt;br&gt;&lt;br&gt;There are also scripts which are started when the interface is brought up or
&lt;br&gt;down. /etc/ppp/ip-up ... you can enter some specific rules there.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;E:S
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Fred [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26501592&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fredbus@...&lt;/a&gt;] 
&lt;br&gt;Sent: Dienstag, 24. November 2009 19:21
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26501592&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;poptop-server@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [Poptop-server] PPTP and iptables problem
&lt;br&gt;&lt;br&gt;Well my problem is that I can't connect to any websites through the
&lt;br&gt;VPN. They just time out. When I clear all iptables rules, it works
&lt;br&gt;fine.
&lt;br&gt;&lt;br&gt;PPTP on the server has a WAN IP (eth0) and gives a LAN IP to the PPTP
&lt;br&gt;client (192.168.0.100) when connecting to the server.
&lt;br&gt;&lt;br&gt;So it must be some iptables rule, but I cannot find it at all...
&lt;br&gt;&lt;br&gt;On Tue, Nov 24, 2009 at 6:13 PM, Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26501592&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;&amp;gt;
&lt;br&gt;wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt; I am happily running PPTP/Poptop on Debian 5.0 as a server, connecting
&lt;br&gt;&amp;gt;&amp;gt; with a Windows VPN client. It works fine if iptables is disabled, but
&lt;br&gt;&amp;gt;&amp;gt; when I enable it, I get problems.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What problems do you have? All we know is that you see some iptables
&lt;br&gt;&amp;gt; 'denied' messages.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I have these rules:
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p gre -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -s 0/0 -d (server IP) --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; This lets me connect to the server, but when I try to send traffic
&lt;br&gt;&amp;gt;&amp;gt; over the link (eg visiting a website), syslog shows me this error
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Nov 24 17:56:23 bevc kernel: [3906338.922822] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=1 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;&amp;gt; Nov 24 17:56:26 bevc kernel: [3906341.923159] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=13 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; That appears to be your peer sending DHCP client discovery messages.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ppp0 is the pptp connection on the server. (default) and pptp
&lt;br&gt;&amp;gt;&amp;gt; allocates 192.168.0.100 to the client
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any idea how to solve this? I have spent hours trying to come up with
&lt;br&gt;&amp;gt;&amp;gt; the correct iptables rule, but can't find it.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;----------------------------------------------------------------------------
&lt;br&gt;--
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus
&lt;br&gt;on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26501592&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26501592&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26501592.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26500978</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-24T10:21:14Z</published>
	<updated>2009-11-24T10:21:14Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">Well my problem is that I can't connect to any websites through the
&lt;br&gt;VPN. They just time out. When I clear all iptables rules, it works
&lt;br&gt;fine.
&lt;br&gt;&lt;br&gt;PPTP on the server has a WAN IP (eth0) and gives a LAN IP to the PPTP
&lt;br&gt;client (192.168.0.100) when connecting to the server.
&lt;br&gt;&lt;br&gt;So it must be some iptables rule, but I cannot find it at all...
&lt;br&gt;&lt;br&gt;On Tue, Nov 24, 2009 at 6:13 PM, Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26500978&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt; I am happily running PPTP/Poptop on Debian 5.0 as a server, connecting
&lt;br&gt;&amp;gt;&amp;gt; with a Windows VPN client. It works fine if iptables is disabled, but
&lt;br&gt;&amp;gt;&amp;gt; when I enable it, I get problems.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What problems do you have? All we know is that you see some iptables
&lt;br&gt;&amp;gt; 'denied' messages.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I have these rules:
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p gre -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt; -A INPUT -p tcp -s 0/0 -d (server IP) --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; This lets me connect to the server, but when I try to send traffic
&lt;br&gt;&amp;gt;&amp;gt; over the link (eg visiting a website), syslog shows me this error
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Nov 24 17:56:23 bevc kernel: [3906338.922822] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=1 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;&amp;gt; Nov 24 17:56:26 bevc kernel: [3906341.923159] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt;&amp;gt; PREC=0x00 TTL=128 ID=13 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; That appears to be your peer sending DHCP client discovery messages.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; ppp0 is the pptp connection on the server. (default) and pptp
&lt;br&gt;&amp;gt;&amp;gt; allocates 192.168.0.100 to the client
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any idea how to solve this? I have spent hours trying to come up with
&lt;br&gt;&amp;gt;&amp;gt; the correct iptables rule, but can't find it.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26500978&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26500978.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26499845</id>
	<title>Re: PPTP and iptables problem</title>
	<published>2009-11-24T09:13:34Z</published>
	<updated>2009-11-24T09:13:34Z</updated>
	<author>
		<name>Charlie Brady-13</name>
	</author>
	<content type="html">&lt;br&gt;On Tue, 24 Nov 2009, Frederick Gordts wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Hello &amp;nbsp;list,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I am happily running PPTP/Poptop on Debian 5.0 as a server, connecting
&lt;br&gt;&amp;gt; with a Windows VPN client. It works fine if iptables is disabled, but
&lt;br&gt;&amp;gt; when I enable it, I get problems.
&lt;br&gt;&lt;br&gt;What problems do you have? All we know is that you see some iptables 
&lt;br&gt;'denied' messages.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I have these rules:
&lt;br&gt;&amp;gt; -A INPUT -p tcp --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p gre -j ACCEPT
&lt;br&gt;&amp;gt; -A INPUT -p tcp -s 0/0 -d (server IP) --dport 1723 -j ACCEPT
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; This lets me connect to the server, but when I try to send traffic
&lt;br&gt;&amp;gt; over the link (eg visiting a website), syslog shows me this error
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Nov 24 17:56:23 bevc kernel: [3906338.922822] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt; PREC=0x00 TTL=128 ID=1 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&amp;gt; Nov 24 17:56:26 bevc kernel: [3906341.923159] iptables denied: IN=ppp0
&lt;br&gt;&amp;gt; OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;&amp;gt; PREC=0x00 TTL=128 ID=13 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;/div&gt;&lt;br&gt;That appears to be your peer sending DHCP client discovery messages.
&lt;br&gt;&lt;br&gt;&amp;gt; ppp0 is the pptp connection on the server. (default) and pptp
&lt;br&gt;&amp;gt; allocates 192.168.0.100 to the client
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Any idea how to solve this? I have spent hours trying to come up with
&lt;br&gt;&amp;gt; the correct iptables rule, but can't find it.
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26499845&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26499845.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26499711</id>
	<title>PPTP and iptables problem</title>
	<published>2009-11-24T09:06:07Z</published>
	<updated>2009-11-24T09:06:07Z</updated>
	<author>
		<name>Frederick Gordts</name>
	</author>
	<content type="html">Hello &amp;nbsp;list,
&lt;br&gt;&lt;br&gt;I am happily running PPTP/Poptop on Debian 5.0 as a server, connecting
&lt;br&gt;with a Windows VPN client. It works fine if iptables is disabled, but
&lt;br&gt;when I enable it, I get problems.
&lt;br&gt;&lt;br&gt;I have these rules:
&lt;br&gt;-A INPUT -p tcp --dport 1723 -j ACCEPT
&lt;br&gt;-A INPUT -p gre -j ACCEPT
&lt;br&gt;-A INPUT -p tcp -s 0/0 -d (server IP) --dport 1723 -j ACCEPT
&lt;br&gt;&lt;br&gt;This lets me connect to the server, but when I try to send traffic
&lt;br&gt;over the link (eg visiting a website), syslog shows me this error
&lt;br&gt;&lt;br&gt;Nov 24 17:56:23 bevc kernel: [3906338.922822] iptables denied: IN=ppp0
&lt;br&gt;OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;PREC=0x00 TTL=128 ID=1 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;Nov 24 17:56:26 bevc kernel: [3906341.923159] iptables denied: IN=ppp0
&lt;br&gt;OUT= MAC= SRC=192.168.0.100 DST=255.255.255.255 LEN=328 TOS=0x00
&lt;br&gt;PREC=0x00 TTL=128 ID=13 PROTO=UDP SPT=68 DPT=67 LEN=308
&lt;br&gt;&lt;br&gt;ppp0 is the pptp connection on the server. (default) and pptp
&lt;br&gt;allocates 192.168.0.100 to the client
&lt;br&gt;&lt;br&gt;Any idea how to solve this? I have spent hours trying to come up with
&lt;br&gt;the correct iptables rule, but can't find it.
&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;Fred
&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26499711&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PPTP-and-iptables-problem-tp26499711p26499711.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26494618</id>
	<title>poptop+freeradius</title>
	<published>2009-11-24T03:30:05Z</published>
	<updated>2009-11-24T03:30:05Z</updated>
	<author>
		<name>Oguzhan Kayhan</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;I made a configuration for freeradius+pptp+mysql
&lt;br&gt;&lt;br&gt;Everythings working great..Except some minor problems..
&lt;br&gt;Here's follows..
&lt;br&gt;&lt;br&gt;I am checking radacct table on mysql to see the logs..
&lt;br&gt;Ok. i can see connection dates..total data trasnfers.. username etc..but..
&lt;br&gt;it doesnt show callingstationid for the user that connects to vpn..
&lt;br&gt;Just the framedIpAddress that user gets..
&lt;br&gt;Does anybody had such problem.. or is there any way to log the callingip
&lt;br&gt;addresses on mysql also???
&lt;br&gt;&lt;br&gt;Second problem..
&lt;br&gt;Is there a way to disconnect pptp user via radius disconnect packet??
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks..
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26494618&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/poptop%2Bfreeradius-tp26494618p26494618.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26478446</id>
	<title>Re: Debian server: PPTP over SSH, for MICROSOFT XP  CLIENT?</title>
	<published>2009-11-23T05:51:50Z</published>
	<updated>2009-11-23T05:51:50Z</updated>
	<author>
		<name>Charlie Brady-13</name>
	</author>
	<content type="html">&lt;br&gt;On Sun, 22 Nov 2009, yellow protoss wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Hi
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; It has nothing to do with consulting. Linux is GNU free. And everyone buy
&lt;br&gt;&amp;gt; using Linux is contributing to its success.
&lt;br&gt;&amp;gt; If you have no time, ok, I do understand.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Look on forums, e.g. Ubuntuforums, the community is really nice and everyone
&lt;br&gt;&amp;gt; is helping each other.
&lt;br&gt;&lt;br&gt;Listen &amp;quot;yellow&amp;quot;, if you want to ask questions of the community, don't send 
&lt;br&gt;email directly to me. Ask the mailing list. If you send questions directly 
&lt;br&gt;to me, then accept what answer I give you, and don't complain to &amp;quot;the 
&lt;br&gt;community&amp;quot;.
&lt;br&gt;&lt;br&gt;Please take the time to read this:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.eyrie.org/~eagle/faqs/questions.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.eyrie.org/~eagle/faqs/questions.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Your proposal is impractical, since GRE packets cannot be forwarded over 
&lt;br&gt;an SSH connection.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Have a nice sunday,
&lt;br&gt;&amp;gt; Best regards
&lt;br&gt;&amp;gt; Y.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Sat, Nov 21, 2009 at 6:09 PM, Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478446&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;&amp;gt;wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; On Sat, 21 Nov 2009, yellow protoss wrote:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; I have several questions, if you dont mind.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Sorry, I don't do PPTP consulting.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; PPTP is it secured over the whole net?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; *PPTP* uses TCP *port* 1723.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Can PPTP be made secured to work like a windows server 2000, I mean, it
&lt;br&gt;&amp;gt; &amp;gt; has
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; great potential.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; It is so easy to make it work.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; just apt-get install
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; the only missing would be a security that wouldnt be SSL since it is very
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; hard to configure.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ... hmmm still thinking how to make PPTP work over the net, to access my
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; home in all security.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://yellowprotoss.ye.funpic.org/website/pptp_over_ssh/PPTP_SECURED_UBUNTU.jpg&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://yellowprotoss.ye.funpic.org/website/pptp_over_ssh/PPTP_SECURED_UBUNTU.jpg&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Best regards
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Y.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; On Sat, Nov 21, 2009 at 3:51 PM, Charlie Brady &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478446&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;charlie_brady@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; On Sat, 21 Nov 2009, yellow protoss wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; That idea is quite nice, no? or has issues.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; No, it has issues. SSH can only forward TCP connections. PPTP uses GRE
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; packets as transport.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; ---
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Charlie
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;/div&gt;&lt;br&gt;---
&lt;br&gt;Charlie
&lt;br&gt;&lt;br&gt;&lt;br&gt;------------------------------------------------------------------------------
&lt;br&gt;Let Crystal Reports handle the reporting - Free Crystal Reports 2008 30-Day 
&lt;br&gt;trial. Simplify your report design, integration and deployment - and focus on 
&lt;br&gt;what you do best, core application coding. Discover what's new with
&lt;br&gt;Crystal Reports now. &amp;nbsp;&lt;a href=&quot;http://p.sf.net/sfu/bobj-july&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://p.sf.net/sfu/bobj-july&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Poptop-server mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26478446&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Poptop-server@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://lists.sourceforge.net/lists/listinfo/poptop-server&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://lists.sourceforge.net/lists/listinfo/poptop-server&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/poptop-server-f4437.html&quot; embed=&quot;fixTarget[4437]&quot; target=&quot;_top&quot; &gt;poptop-server&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-Debian-server%3A-PPTP-over-SSH%2C-for-MICROSOFT-XP-%09CLIENT--tp26463461p26478446.html" />
</entry>

</feed>
