Hi, I will implement vpn using pptp. Win-XP client ---> Bering ---> Internet ---> PPTP Server Win-XP does not become access in PPTP(Server). My config : Bering #edit /etc/shorewall/rules ACCEPT fw net tcp 1723 ACCEPT fw net 47 - #lsmod Module Pages Used by ip_nat_irc 2384 0 (unused) ip_nat_ftp 2960 0 (unused) ip_conntrack_irc 3056 1 ip_conntrack_ftp 3824 1 ip_nat_pptp 3324 0 (unused) ip_conntrack_pptp 5556 1 ip_nat_proto_gre 1912 0 (unused) ip_conntrack_proto_gre 4468 0 [ip_nat_pptp ip_conntrack_pptp] 8139too 13308 2 mii 912 0 [8139too] #edit /var/log/syslog Mar 24 13:48:18 firewall kernel: ip_conntrack_pptp.c:init: ip_conntrack_pptp.c: registering helper Mar 24 13:48:18 firewall kernel: ip_nat_pptp.c:init: init_module Mar 24 13:48:18 firewall kernel: eth0: Setting half-duplex based on auto-negotiated partner ability 0000. Mar 24 13:48:18 firewall kernel: eth0: Setting half-duplex based on auto-negotiated partner ability 0000. Mar 24 13:48:18 firewall kernel: eth1: Setting half-duplex based on auto-negotiated partner ability 0000. Mar 24 13:48:18 firewall kernel: grsec: time set by (hwclock:1135) UID(0) EUID(0), parent (S50hwclock:13991) UID(0) EUID(0) Mar 24 13:48:25 firewall root: Shorewall Started Mar 24 13:48:25 firewall /usr/sbin/cron[28753]: (CRON) INFO (pidfile fd = 3) Mar 24 13:48:25 firewall /usr/sbin/cron[27942]: (CRON) STARTUP (fork ok) Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: ctinfo = 2, skipping Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir ORIG at hook PREROUTING Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: pptp packet too short Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: no full PPTP header, can't track Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: pptp packet too short Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir REPLY at hook POSTROUTING Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_outbound_pkt: inbound control message START_SESSION_REQUEST Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: sstate: 0->3, cstate: 0->0 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir ORIG at hook PREROUTING Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: no full PPTP header, can't track Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: pptp packet too short Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir REPLY at hook POSTROUTING Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_inbound_pkt: inbound control message START_SESSION_REPLY Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: sstate: 3->4, cstate: 0->0 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir REPLY at hook POSTROUTING Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_outbound_pkt: inbound control message OUT_CALL_REQUEST Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_outbound_pkt: OUT_CALL_REQUEST, CID=8000 Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: sstate: 4->4, cstate: 0->2 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir ORIG at hook PREROUTING Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_outbound_pkt: altering call id from 0x8000 to 0x054d Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_inbound_pkt: inbound control message OUT_CALL_REPLY Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_inbound_pkt: OUT_CALL_REPLY, CID=54D, PCID=0 Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_inbound_pkt: tcph->seq=1296293586, exp.seq=3537781595 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_add: ip_ct_gre_keymap_addadding new entry c0cd4540: keymap: key_reply=0x0 xxx.221.53.227:0x54d0000 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_add: tuple c0cd4548: 47 xxx.221.53.227:0x054d0000 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: sstate: 4->4, cstate: 2->3 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_del: trying to delete key for tuple xxx.221.53.227:0x54d0000 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_del: tuple c020fe1c: 47 xxx.221.53.227:0x054d0000 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_del: ip_ct_gre_keymap_deldeleting keymap c0cd4540 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_inbound_pkt: successfully changed expect Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_add: ip_ct_gre_keymap_addadding new entry c0cd4560: keymap: key_reply=0x80 xxx.221.53.227:0x54d0000 -> xxx.52.247.191:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_add: tuple c0cd4568: 47 xxx.221.53.227:0x054d0000 -> xxx.52.247.191:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_inbound_pkt: altering peer call id from 0x054d to 0x8000 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir REPLY at hook POSTROUTING Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x54d0000 -> xxx.52.247.191:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fe90: 47 xxx.221.53.227:0x054d0000 -> xxx.52.247.191:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: ip_ct_gre_key_invert: found inverse key 0x8000 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:gre_new: gre_new: xxx.221.53.227:0x54d0000 -> xxx.52.247.191:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:gre_new: tuple c031d1a0: 47 xxx.221.53.227:0x054d0000 -> xxx.52.247.191:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_expectfn: increasing timeouts Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_nat_expected: we have a connection! Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_nat_expected: change dest ip to 192.168.1.1 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.52.247.191:0x80000000 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c031d1c0: 47 xxx.52.247.191:0x80000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: ip_ct_gre_key_invert: found inverse key 0x54d Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x54d0000 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fe2c: 47 xxx.221.53.227:0x054d0000 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x54d0000 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fe2c: 47 xxx.221.53.227:0x054d0000 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x54d0000 -> xxx.52.247.191:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fdf0: 47 xxx.221.53.227:0x054d0000 -> xxx.52.247.191:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: ip_ct_gre_key_invert: found inverse key 0x8000 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_nat_expected: we have a connection! Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_nat_expected: change src ip to 84.254.32.192 Mar 24 13:49:42 firewall kernel: ip_nat_pptp.c:pptp_nat_expected: change 'src' key to 0x80 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple 192.168.1.1:0x54d0000 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c031d1c0: 47 192.168.1.1:0x054d0000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x80 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fd50: 47 xxx.221.53.227:0x00000080 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x80 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fd50: 47 xxx.221.53.227:0x00000080 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x54d0000 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fd14: 47 xxx.221.53.227:0x054d0000 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_nat_proto_gre.c:gre_manip_pkt: call_id -> 0x0000 Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: no full PPTP header, can't track Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_outbound_pkt: inbound control message WAN_ERROR_NOTIFY Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:pptp_outbound_pkt: invalid WAN_ERROR_NOTIFY (TY=15) Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: sstate: 4->4, cstate: 3->3 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple 192.168.1.1:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fe90: 47 192.168.1.1:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:gre_new: gre_new: 192.168.1.1:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:gre_new: tuple c031d2e0: 47 192.168.1.1:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x0 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c031d300: 47 xxx.221.53.227:0x00000000 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple 192.168.1.1:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fe2c: 47 192.168.1.1:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple 192.168.1.1:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fe2c: 47 192.168.1.1:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple 192.168.1.1:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fdf0: 47 192.168.1.1:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.221.53.227:0x0 -> 192.168.1.1:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c031d300: 47 xxx.221.53.227:0x00000000 -> 192.168.1.1:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.52.247.191:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fc74: 47 xxx.52.247.191:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple xxx.52.247.191:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fc74: 47 xxx.52.247.191:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: trying to invert key for tuple 192.168.1.1:0x0 -> xxx.221.53.227:1:0x880b Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: tuple c020fc38: 47 192.168.1.1:0x00000000 -> xxx.221.53.227:0x880b0100 Mar 24 13:49:42 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_key_invert: : not found Mar 24 13:49:42 firewall kernel: ip_nat_proto_gre.c:gre_manip_pkt: call_id -> 0x0000 Mar 24 13:49:42 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: no full PPTP header, can't track Mar 24 13:49:44 firewall kernel: ip_nat_proto_gre.c:gre_manip_pkt: call_id -> 0x0000 Mar 24 13:50:11 firewall last message repeated 24 times Mar 24 13:50:12 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: RST/FIN received, timeouting GRE Mar 24 13:50:12 firewall kernel: ip_conntrack_pptp.c:pptp_timeout_related: setting timeout of conntrack c031d190 to 0 Mar 24 13:50:12 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: no full PPTP header, can't track Mar 24 13:50:12 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: RST/FIN received, timeouting GRE Mar 24 13:50:12 firewall kernel: ip_conntrack_pptp.c:pptp_timeout_related: setting timeout of conntrack c031d190 to 0 Mar 24 13:50:12 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: no full PPTP header, can't track Mar 24 13:50:12 firewall kernel: ip_conntrack_proto_gre.c:gre_destroy: destroying c031d190 Mar 24 13:50:12 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_del: trying to delete key for tuple xxx.221.53.227:0x54d0000 -> xxx.52.247.191:1:0x880b Mar 24 13:50:12 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_del: tuple c031d1a0: 47 xxx.221.53.227:0x054d0000 -> xxx.52.247.191:0x880b0100 Mar 24 13:50:12 firewall kernel: ip_conntrack_proto_gre.c:ip_ct_gre_keymap_del: ip_ct_gre_keymap_deldeleting keymap c0cd4560 Mar 24 13:50:12 firewall kernel: ip_conntrack_pptp.c:conntrack_pptp_help: no full PPTP header, can't track Mar 24 13:50:12 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:50:12 firewall kernel: ip_nat_pptp.c:tcp_help: pptp packet too short Mar 24 13:50:12 firewall kernel: ip_nat_pptp.c:tcp_help: entering Mar 24 13:50:12 firewall kernel: ip_nat_pptp.c:tcp_help: Not touching dir REPLY at hook POSTROUTING Mar 24 13:50:41 firewall kernel: ip_conntrack_proto_gre.c:gre_destroy: no master for ct c031d2d0 Thanks. �+w�zf��+,��좷�o!���^��jY��x,��Ӆ�݅�]>��*%���i�&��-�,ކ�i�����.�ǟ����r���yثy�i����M4���y����j)b� b��^i��z�b��,���y�+��m����+-��.�ǟ�����+-��b�ا~��y����DP��i��^i�k�7�������������ځ��v�"w_=�f
