Koozali.org: home of the SME Server

VPN HELP!!!!

Rockem

VPN HELP!!!!
« on: August 05, 2004, 04:22:51 PM »
I'm running SME 6.0.1-01 custom at home and at the office. I can not VPN in from either side can someone please help me out.

Offline arnoldob

  • *
  • 183
  • +0/-0
Kernel update can break VPN
« Reply #1 on: August 05, 2004, 09:50:54 PM »
I had a similar problem. I had updated the kernel. The new version was not compatable with VPN. See Ian Wells' kernel howto for the versions involved:
http://www.wellsi.com/sme/kernel/kernel.html

uname -r
Will give you your current kernel version

Here's an excerpt from the Howto:
"Before starting it is important to understand that ppp-modules (which is required for PPTP VPN) has a dependency on (and will only work with) a particular version of the kernel. You won't have PPTP VPN capability until someone builds a ppp-modules RPM built for the kernel version you use."

Also see this thread for an updated kernel supporting PPTP:
http://forums.contribs.org/index.php?topic=23444.0

Hope that helps.
Tampa, FL USA

Rockem

VPN Help
« Reply #2 on: August 06, 2004, 03:22:18 PM »
I still have problems I get a Error 743. PPP link Control Protocal was terminated

I really need to get this running Please help.

Offline arnoldob

  • *
  • 183
  • +0/-0
VPN HELP!!!!
« Reply #3 on: August 06, 2004, 04:20:44 PM »
Have a look here:
http://forums.contribs.org/index.php?topic=21106.0

It shows a fix for the same error.
Tampa, FL USA

Rockem

VPN HELP!!!!
« Reply #4 on: August 06, 2004, 05:36:53 PM »
Nope no help there.I running two SME 6.0.1-01 Custom Computers on two different locations both with staic IP's and Windows Xp at both locations. I can not VPN either way but I can VPN in the same location to it's server it's connected too.

This really a pain. I need to get this running.

Offline crazybob

  • *****
  • 894
  • +0/-0
    • Stalzer R&D
VPN HELP!!!!
« Reply #5 on: August 06, 2004, 08:00:59 PM »
Check your settings for the vpn connection on your XP box. the setting for I think password has to be the maximum setting.Also look around in the advanced panel and put a check mark in the singlelink as multi link ( or something like that, I do not have the window in front of me)

Bob
If you think you know whats going on, you obviously have no idea whats going on!

ryan

VPN HELP!!!!
« Reply #6 on: August 07, 2004, 06:48:12 AM »
Rockem,

This problem/bug/issue has been discussed many times.  If you need a fix, remove v6 of SME at one end, or downgrade it.  This issue has been discussed since Dec or Jan, and it still exists.  

I found a work around, but it requires 2 additional low end (PII or better & 128mb ram) PCs and 6 nic cards.  Install IPCop on the two additional PCs and make use of green, orange, and red zones.  IPCop will then be your connection to the internet connection (at both sites).  I keep SME in server gateway mode and connect the external nic to the DMZ (orange lan) of IPCop  Your SME external gateway is the orange IP address of the IPCop server.  You can then port forward pptp from IPCop to your SME server to accept pptp connections from the internet.  If you only need one way pptp, put a single IPCop at the site you connect pptp from.    Adding IPCop as described will provide you with 2 gateways on the lan...simply use the IPCop gateway if your going to connect pptp to a remote SME 6 server.  Or use server manager to define the static address in remote network and use the green IP address as the router...this will allow SME on either end to route traffic to your static IP through IPCop (by passing SME).  

If you use SME for dhcp, your lan clients will use SME as the default gateway.  Use IPCop for dhcp, they will use IPCop gateway.  Or you can use group policy/MS dhcp to control proxy & router settings if you have a 2k or 2k3 AD server running.

Personally, I like IPCop as a router.  It is very easy to use IPSEC vpn between sites and you can use cheap linksys vpn routers as an IPSEC vpn end point.  I have several remote offices connected to a central IPCop server.  These remote offices use either a linksys or IPCop server.  It is very stable.  IPCop is opensource...free!!  I keep SME for services like proxy, pop, smtp, squidguard, sarge, ftp, ssh, etc....

Hope this helps you find a solution.

ryan

Offline MSmith

  • *
  • 675
  • +0/-0
I've never had a problem after following these:
« Reply #7 on: August 07, 2004, 12:24:25 PM »
http://www.domain-logic.com/support/secure_tunnel_XP.htm

http://www.domain-logic.com/support/secure_tunnel_w2k.htm

SP4 for Win2K is essential.

I stress that I have had NO problems connecting to 6.0.1 and 6.0.1-01 servers using this configuration.
...

ryan

VPN HELP!!!!
« Reply #8 on: August 07, 2004, 05:02:50 PM »
M Smith,

This vpn problem only exists when your VPN client (2k or XP) is behind an SME 6.0 box and attempts to pptp to a remote SME 6.0 box.  If the client behind any other type of firewall, even a SME 5.6 or less, the vpn connection will work fine.  

I was running with SME 5.6 at work and SME 6.0 at home since March04.  No problems doing pptp either direction.  When I upgraded my work servers to 6.0, vpn no longer works.  All my vpn users (that do not have SME 6.0 at home) have no problems connecting.  

This issue has nothing to do with the client vpn settings and is specifically related to pptp and SME 6.0 server.  Many others have posted this same issue on contribs.org in the past.  

ryan