News: This forum is now permanently frozen.
Pages: [1]
Topic: VPN PPTP drop connection - 1.33  (Read 3193 times)
« on: June 28, 2011, 18:20:25 »
odlanor *
Posts: 1

Jun 28 17:30:09   mpd: COMPPROTO VJCOMP, 16 comp. channels, no comp-cid
Jun 28 17:30:09   mpd: [pt0] IPCP: SendConfigReq #55
Jun 28 17:30:09   mpd: IPADDR 192.168.90.100
Jun 28 17:30:09   mpd: [pt0] IPCP: rec'd Configure Ack #55 (Ack-Sent)
Jun 28 17:30:09   mpd: IPADDR 192.168.90.100
Jun 28 17:30:09   mpd: [pt0] IPCP: state change Ack-Sent --> Opened
Jun 28 17:30:09   mpd: [pt0] IPCP: LayerUp
Jun 28 17:30:09   mpd: 192.168.90.100 -> 192.168.90.80
Jun 28 17:30:09   mpd: [pt0] IFACE: Up event
Jun 28 17:30:09   mpd: [pt0] rec'd unexpected protocol IP
Jun 28 17:39:17   mpd: last message repeated 20 times
Jun 28 17:39:17   mpd: [pt0] LCP: no reply to 1 echo request(s)
Jun 28 17:39:27   mpd: [pt0] LCP: no reply to 2 echo request(s)
Jun 28 17:39:31   mpd: pptp0: ctrl connection closed by peer
Jun 28 17:39:31   mpd: pptp0: killing connection with xxx.xxx.xxx.xxx 11607
Jun 28 17:39:31   mpd: pptp0-0: killing channel
Jun 28 17:39:31   mpd: [pt0] PPTP call terminated
Jun 28 17:39:31   mpd: [pt0] link: DOWN event
Jun 28 17:39:31   mpd: [pt0] LCP: Close event
Jun 28 17:39:31   mpd: [pt0] LCP: state change Opened --> Closing
Jun 28 17:39:31   mpd: [pt0] AUTH: Accounting data for user user1: 566 seconds, 972894 octets in, 16457275 octets out
Jun 28 17:39:31   mpd: [pt0] Bundle up: 0 links, total bandwidth 9600 bps
Jun 28 17:39:31   mpd: [pt0] IPCP: Close event
Jun 28 17:39:31   mpd: [pt0] IPCP: state change Opened --> Closing
Jun 28 17:39:31   mpd: [pt0] IPCP: SendTerminateReq #56
Jun 28 17:39:31   mpd: [pt0] error writing len 8 frame to bypass: Network is down
Jun 28 17:39:31   mpd: [pt0] IPCP: LayerDown
Jun 28 17:39:31   mpd: [pt0] IFACE: Down event
Jun 28 17:39:31   mpd: [pt0] CCP: Close event
Jun 28 17:39:31   mpd: [pt0] CCP: state change Opened --> Closing
Jun 28 17:39:31   mpd: [pt0] CCP: SendTerminateReq #28
Jun 28 17:39:31   mpd: [pt0] error writing len 8 frame to bypass: Network is down
Jun 28 17:39:31   mpd: [pt0] CCP: LayerDown
Jun 28 17:39:31   mpd: [pt0] IPCP: Down event
Jun 28 17:39:31   mpd: [pt0] IPCP: LayerFinish
Jun 28 17:39:31   mpd: [pt0] No NCPs left. Closing links...
Jun 28 17:39:31   mpd: [pt0] closing link "pt0"...
Jun 28 17:39:31   mpd: [pt0] IPCP: state change Closing --> Initial
Jun 28 17:39:31   mpd: [pt0] CCP: Down event
« Reply #1 on: September 08, 2011, 18:26:21 »
pvanulden *
Posts: 1

I am also having this exact same issue.  Here is my setup:

m0n0wall has TWO (2) physical interfaces, one on the internet, the other as 10.1.1.1 which is the gateway for our LAN subnet (10.1.1.0).   The PPTP server address is 10.1.1.254 with a remote IP range of 10.1.1.80/28.  We use Windows Server 2008 RADIUS for authentication.  In the firewall, ALL traffic is allowed on both the LAN and PPTP interfaces.  On the WAN interface, ALL traffic is allowed from PPTP clients to LAN net and from LAN net to PPTP clients.

VPN clients can connect and authenticate and everything works but, 1:10 after connecting, the m0n0wall log reports:

Sep 8 13:49:22    mpd: 10.1.1.254 -> 10.1.1.80
Sep 8 13:49:22    mpd: [pt0] IFACE: Up event
Sep 8 13:50:32    mpd: [pt0] LCP: no reply to 1 echo request(s)
Sep 8 13:50:42    mpd: [pt0] LCP: no reply to 2 echo request(s)
Sep 8 13:50:52    mpd: [pt0] LCP: no reply to 3 echo request(s)
Sep 8 13:51:02    mpd: [pt0] LCP: no reply to 4 echo request(s)
Sep 8 13:51:12    mpd: [pt0] LCP: no reply to 5 echo request(s)
Sep 8 13:51:12    mpd: [pt0] LCP: peer not responding to echo requests
Sep 8 13:51:12    mpd: [pt0] LCP: state change Opened --> Stopping

And then disconnects the user.  If we setup a continuous ping from the VPN client to the LAN gateway (10.1.1.1), then the link does *NOT* get disconnected and we don't see any echo request failures in the log.  I'm guessing mpd monitors the line, if it sees that it is idle, it then attempts to contact the client and if it doesn't get any response, disconnects.  Initially, the client didn't have ICMP allowed in it's firewall and therefore couldn't be pinged from the LAN.  Once enabling ICMP, I was then able to ping the client's IP but mpd still reported echo request failures and disconnects.

Previously, we had mpd running on a FreeBSD server on the LAN and forwarded PPTP into it from the m0n0wall and never had this problem.  My thought is that there is some option in mpd on m0n0wall which may be causing this to happen.

Any ideas?

Thanks in advance,
Philip
 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines