Koozali.org: home of the SME Server

I was wrong! The VPN is stable. Read explanation.

pistonpilot

I was wrong! The VPN is stable. Read explanation.
« on: February 17, 2004, 07:37:54 AM »
I have been running a ClarkConnect box since I thought I hosed my qmail.  I'm a linux newbie but I learn fast.  I always suspected that connecting to a PPTP VPN through a  VPN server was the problem and now I've had my theory confirmed.  

I was getting the dreaded 619 error, but as soon as turned off the VPN service PPTP and connected, I was able to connect to my clients boxes with no problems.

Here is the text from ClarkConnect support:

The IPsec VPN is rock solid -- PPTP VPN is another story.  There are a number of issues with PPTP -- it's both a protocol issue (PPTP and NAT do not mix very well) and Linux issue.  The trouble spots:

- PPTP connection tracking will not allow multiple connections from the same IP.  This happens when two or more users connect to the same PPTP server from behind the same firewall.  This is a protocol limitation.

- PPTP connections crossing a gateway running a PPTP server can create unstable connections.  In other words, if you run a PPTP server on your gateway, desktop machines *behind* the gateway should not be connecting to other PPTP servers.  This is a Linux implementation issue.