/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
I'm having some difficulty with getting a PPTP client to communicate
through an IP Masq'ing box. (Yes, I'm aware there are better things to
use than PPTP, but I have to prove this even works first.)
I've gone through the HowTO's for IPChains, IPMasq, and VPNs.
I've set up the system on a 2.2.13 kernel, and compiled it with the
ip_masq modules for things such as ipip, ipgre, ipmasqftp, ipautofw,
ipportfw, etc.
Using tcpdump on both the eth0 and ppp0 interfaces, I can see the client
make it's connection via 1723/TCP and the server respond on 1723/TCP.
Then on eth0 I start seeing "gre encap" packets which don't get masq'd
out via ppp0 as far as I can tell.
The PPTP host sees a connection get initiated, but no logon occurs.
(Since apparently the gre stuff is hanging up at the Linux box.)
My ipchains rules...
(input policy accept)
(forward policy deny)
(output policy accept)
ipchains -A input -s 192.168.1.0/24 -j MASQ
I haven't applied any patches to the 2.2.13 kernel, as I noticed that it
already includes support for GRE (and I've done the "depmod -a" and
"modprobe ip_gre" commands). As I understand PPTP, it establishes the
connection on 1723/TCP and then shifts to IP protocol 47 (GRE) for the
actual communications.
Can anyone help out a poor soul who has spent the last week trying to
get this to work by some means or another. (VPN being the latest
attempt at getting two computers on two LAN's to speak over the
Internet. Port forwarding sure didn't work right.)
--
Digital Wokan
Tribal mage of the electronics age
Guerilla Linux Warrior
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.