Hi,
I try to set up my MPD5 with PPTP, but it still fail after whole weekend, does anyone can give me some adives?(pptp client is windows 7, and error 806)
I use pppoe dialup to internet, the tun0 IP is 220.135.92.208 and re0 also got 192.168.1.2 from ADSL modem
mpd5.conf
As Windows point out this problem might be occur due to firewall configuration, I put these line in ipfw.rules
#VPN GRE
Thanks!
I try to set up my MPD5 with PPTP, but it still fail after whole weekend, does anyone can give me some adives?(pptp client is windows 7, and error 806)
I use pppoe dialup to internet, the tun0 IP is 220.135.92.208 and re0 also got 192.168.1.2 from ADSL modem
mpd5.conf
Code:
startup:
set user foo bar admin
set web self 220.135.92.208 5006
set web open
default:
load pptp_server
pptp_server:
# Define dynamic IP address pool.
set ippool add pool_pptp 192.168.1.50 192.168.1.90
# Create clonable bundle template named B_pptp
create bundle template B_pptp
set iface enable proxy-arp
set iface enable tcpmssfix
set ipcp yes vjcomp
# Specify IP address pool for dynamic assigment.
set ipcp ranges 192.168.1.1/24 ippool pool_pptp
set ipcp dns 168.95.1.1
# The five lines below enable Microsoft Point-to-Point encryption
# (MPPE) using the ng_mppc(8) netgraph node type.
set bundle enable compression
set ccp yes mppc
set mppc yes e40
set mppc yes e128
set mppc yes stateless
# Create clonable link template named L_pptp
create link template L_pptp pptp
# Set bundle template to use
set link action bundle B_pptp
# Multilink adds some overhead, but gives full 1500 MTU.
set link enable multilink
set link no pap chap eap
set link enable chap
set link keep-alive 0 0
set link fsm-timeout 5
set auth enable internal
# We reducing link mtu to avoid GRE packet fragmentation.
set link mtu 1448
# Configure PPTP
set pptp self 220.135.92.208
set pptp enable always-ack
# Allow to accept calls
set link enable incoming
As Windows point out this problem might be occur due to firewall configuration, I put these line in ipfw.rules
#VPN GRE
Code:
$cmd 50000 allow tcp from any to me dst-port 1723
$cmd 51000 allow GRE from any to me
$cmd 52000 allow tcp from me to any dst-port 1723
$cmd 53000 allow GRE from me to any
$cmd 54000 allow tcp from any to me dst-port 47
$cmd 56000 allow tcp from me to any dst-port 47
$cmd 58000 allow udp from any to me dst-port 1723
$cmd 59100 allow udp from me to any dst-port 1723
$cmd 59300 allow udp from any to me dst-port 47
$cmd 59500 allow udp from me to any dst-port 47
Thanks!