Emberek!
Van egy VPN-es problémám, tudtok segíteni?
Linux Debian Sarge-t szeretnék VPN szerverként használni (Kerenel: 2.6.16.16)
XP-alol szeretném kívülről elérn, Linux szokásosan router mögött van...
Problémám az, hogy sehogy nem érem el kintről a gépet a háló ip-jén keresztül, viszont ha a local hálon keresztül indítom kapcslatot (Az XPs VPN kapcsinak a szerver helyi IP-jét adom meg) minden további nélkül indul. Modemen keresztül sem sikerül - a hálótól teljesen független elérni a szervert...
Valami azonosítás környékén lehet a probléma, mert a logfájlokból látszik, hogy a kapcsi el kezd felépülni, az azonosításnál lehet probléma ?!...., ill a XP kapcs is a felhasználó és jelszó ellenörzésnél akad meg. Belülről akkor miért megy?
A tűzfalon engedélyezem a 47-es és 1723-as portot. Ha a tűzfalat kikapcsolom sem történik változás.
1. Syslog (ha az XP-nek a szerver helyi címe kerül beállításra):
May 23 01:16:46 pilot pptpd[2780]: CTRL: Client
192.168.0.100 control connection started
May 23 01:16:46 pilot pptpd[2780]: CTRL: Starting call (launching pppd, opening GRE)
May 23 01:16:46 pilot pppd[2781]: Plugin /usr/lib/pptpd/pptpd-logwtmp.so loaded.
May 23 01:16:46 pilot pppd[2781]: pptpd-logwtmp: $Version$
May 23 01:16:46 pilot pppd[2781]: pppd 2.4.3 started by root, uid 0
May 23 01:16:46 pilot pppd[2781]: using channel 10
May 23 01:16:46 pilot pppd[2781]: Using interface ppp0
May 23 01:16:46 pilot pppd[2781]: Connect: ppp0 <--> /dev/pts/4
May 23 01:16:46 pilot pppd[2781]: sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0xf9ee4feb> <pcomp> <accomp>]
May 23 01:16:46 pilot pptpd[2780]: GRE: Bad checksum from pppd.
May 23 01:16:46 pilot pppd[2781]: rcvd [LCP ConfReq id=0x0 <mru 1400> <magic 0x7bf625a3> <pcomp> <accomp> <callback CBCP>]
May 23 01:16:46 pilot pppd[2781]: sent [LCP ConfRej id=0x0 <callback CBCP>]
May 23 01:16:46 pilot pppd[2781]: rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0xf9ee4feb> <pcomp> <accomp>]
May 23 01:16:46 pilot pppd[2781]: rcvd [LCP ConfReq id=0x1 <mru 1400> <magic 0x7bf625a3> <pcomp> <accomp>]
May 23 01:16:46 pilot pppd[2781]: sent [LCP ConfAck id=0x1 <mru 1400> <magic 0x7bf625a3> <pcomp> <accomp>]
May 23 01:16:46 pilot pppd[2781]: sent [LCP EchoReq id=0x0 magic=0xf9ee4feb]
May 23 01:16:46 pilot pppd[2781]: sent [CHAP Challenge id=0x45 <638c1ca8e4234926a3559ab93cc7542a>, name = "pptpd"]
May 23 01:16:46 pilot pppd[2781]: rcvd [LCP Ident id=0x2 magic=0x7bf625a3 "MSRASV5.10"]
May 23 01:16:46 pilot pppd[2781]: rcvd [LCP Ident id=0x3 magic=0x7bf625a3 "MSRAS-0-MASTPC"]
May 23 01:16:46 pilot pppd[2781]: rcvd [LCP EchoRep id=0x0 magic=0x7bf625a3]
May 23 01:16:46 pilot pppd[2781]: rcvd [CHAP Response id=0x45 <b05eef1fe485eaa3cd3157fbeb597c3c0000000000000000bc0314eb6d3c1b6f210beecee61b182db9baf3e1bf9a451d00>, name = "mf"]
May 23 01:16:46 pilot pppd[2781]: sent [CHAP Success id=0x45 "S=0F1C6A603CA9014C37185D18B8A3AFEBF03BA9E2 M=Access granted"]
May 23 01:16:46 pilot pppd[2781]: sent [CCP ConfReq id=0x1 <mppe +H -M +S +L -D -C>]
May 23 01:16:46 pilot pppd[2781]: rcvd [CCP ConfReq id=0x4 <mppe +H -M +S -L -D +C>]
May 23 01:16:46 pilot pppd[2781]: sent [CCP ConfNak id=0x4 <mppe +H -M +S -L -D -C>]
May 23 01:16:46 pilot pppd[2781]: rcvd [IPCP ConfReq id=0x5 <addr 0.0.0.0> <ms-dns1 0.0.0.0> <ms-wins 0.0.0.0> <ms-dns3 0.0.0.0> <ms-wins 0.0.0.0>]
May 23 01:16:46 pilot pppd[2781]: sent [IPCP TermAck id=0x5]
May 23 01:16:46 pilot pppd[2781]: rcvd [CCP ConfNak id=0x1 <mppe +H -M +S -L -D -C>]
May 23 01:16:46 pilot pppd[2781]: sent [CCP ConfReq id=0x2 <mppe +H -M +S -L -D -C>]
May 23 01:16:46 pilot pppd[2781]: rcvd [CCP ConfReq id=0x6 <mppe +H -M +S -L -D -C>]
May 23 01:16:46 pilot pppd[2781]: sent [CCP ConfAck id=0x6 <mppe +H -M +S -L -D -C>]
May 23 01:16:46 pilot pppd[2781]: rcvd [CCP ConfAck id=0x2 <mppe +H -M +S -L -D -C>]
May 23 01:16:46 pilot pppd[2781]: MPPE 128-bit stateless compression enabled
May 23 01:16:46 pilot pppd[2781]: sent [IPCP ConfReq id=0x1 <compress VJ 0f 01> <addr 192.168.0.200>]
May 23 01:16:46 pilot pppd[2781]: rcvd [IPCP ConfRej id=0x1 <compress VJ 0f 01>]
May 23 01:16:46 pilot pppd[2781]: sent [IPCP ConfReq id=0x2 <addr 192.168.0.200>]
May 23 01:16:46 pilot pppd[2781]: rcvd [IPCP ConfAck id=0x2 <addr 192.168.0.200>]
May 23 01:16:46 pilot pptpd[2780]: CTRL: Ignored a SET LINK INFO packet with real ACCMs!
May 23 01:16:48 pilot pppd[2781]: rcvd [IPCP ConfReq id=0x7 <addr 0.0.0.0> <ms-dns1 0.0.0.0> <ms-wins 0.0.0.0> <ms-dns3 0.0.0.0> <ms-wins 0.0.0.0>]
May 23 01:16:48 pilot pppd[2781]: sent [IPCP ConfRej id=0x7 <ms-dns1 0.0.0.0> <ms-dns3 0.0.0.0>]
May 23 01:16:48 pilot pppd[2781]: rcvd [IPCP ConfReq id=0x8 <addr 0.0.0.0> <ms-wins 0.0.0.0> <ms-wins 0.0.0.0>]
May 23 01:16:48 pilot pppd[2781]: sent [IPCP ConfNak id=0x8 <addr 192.168.0.235> <ms-wins 192.168.0.200> <ms-wins 192.168.0.200>]
May 23 01:16:48 pilot pppd[2781]: rcvd [IPCP ConfReq id=0x9 <addr 192.168.0.235> <ms-wins 192.168.0.200> <ms-wins 192.168.0.200>]
May 23 01:16:48 pilot pppd[2781]: sent [IPCP ConfAck id=0x9 <addr 192.168.0.235> <ms-wins 192.168.0.200> <ms-wins 192.168.0.200>]
May 23 01:16:48 pilot pppd[2781]: found interface eth0 for proxy arp
May 23 01:16:48 pilot pppd[2781]: local IP address 192.168.0.200
May 23 01:16:48 pilot pppd[2781]: remote IP address 192.168.0.235
May 23 01:16:48 pilot pppd[2781]: pptpd-logwtmp.so ip-up ppp0 mf 192.168.0.100
May 23 01:16:48 pilot pppd[2781]: Script /etc/ppp/ip-up started (pid 2789)
May 23 01:16:48 pilot pppd[2781]: Script /etc/ppp/ip-up finished (pid 2789), status = 0x0
2. Kintrol, (amikor az ISP-től kapott IP-t állítom be)
May 23 01:39:29 pilot pptpd[2962]: CTRL: Client
84.0.181.25 control connection started
May 23 01:39:29 pilot pptpd[2962]: CTRL: Starting call (launching pppd, opening GRE)
May 23 01:39:29 pilot pppd[2963]: Plugin /usr/lib/pptpd/pptpd-logwtmp.so loaded.
May 23 01:39:29 pilot pppd[2963]: pptpd-logwtmp: $Version$
May 23 01:39:29 pilot pppd[2963]: pppd 2.4.3 started by root, uid 0
May 23 01:39:29 pilot pppd[2963]: using channel 16
May 23 01:39:29 pilot pppd[2963]: Using interface ppp0
May 23 01:39:29 pilot pppd[2963]: Connect: ppp0 <--> /dev/pts/0
May 23 01:39:29 pilot pppd[2963]: sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0x3e956f2d> <pcomp> <accomp>]
May 23 01:39:29 pilot pptpd[2962]: GRE: Bad checksum from pppd.
May 23 01:39:32 pilot pppd[2963]: sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0x3e956f2d> <pcomp> <accomp>]
May 23 01:39:56 pilot last message repeated 8 times
May 23 01:39:59 pilot pppd[2963]: LCP: timeout sending Config-Requests
May 23 01:39:59 pilot pppd[2963]: Connection terminated.
May 23 01:39:59 pilot pppd[2963]: using channel 17
May 23 01:39:59 pilot pppd[2963]: Using interface ppp0
May 23 01:39:59 pilot pppd[2963]: Connect: ppp0 <--> /dev/pts/0
May 23 01:39:59 pilot pppd[2963]: sent [LCP ConfReq id=0x2 <asyncmap 0x0> <auth chap MS-v2> <magic 0xb2f4e051> <pcomp> <accomp>]
May 23 01:39:59 pilot pppd[2963]: sent [LCP TermReq id=0x3]
May 23 01:39:59 pilot pppd[2963]: tcflush failed: Bad file descriptor
May 23 01:39:59 pilot pppd[2963]: tcsetattr: Invalid argument (line 1010)
May 23 01:39:59 pilot pppd[2963]: Exit.
May 23 01:39:59 pilot pptpd[2962]: GRE: read(fd=4,buffer=804e6c0,len=8196) from PTY failed: status = -1 error = Input/output error, usually caused by unexpected termination of pppd, check option syntax and pppd logs
May 23 01:39:59 pilot pptpd[2962]: CTRL: PTY read or GRE write failed (pty,gre)=(4,5)
May 23 01:39:59 pilot pptpd[2962]: CTRL: Reaping child PPP[2963]
May 23 01:39:59 pilot pptpd[2962]: CTRL: Client 84.0.181.25 control connection finished
3. pilot:/etc/ppp# cat pptpd-options
debug
name pptpd
domain intranet.piloto.no-ip.org
#Csak MS-CHAP v2-.t engedünk
-chap
-mschap
require-mschap-v2
require-mppe
#Er.s titkosítás
#mppe required,stateless,no56,no40
#Bels. hálózat címei
#ms-dns 192.168.1.4
ms-wins 192.168.0.200
netmask 255.255.255.0
nodefaultroute
proxyarp
lock
Szerkesztette: fortyfive 2006. 05. 23. 01:15 -kor