Could this be worthy of a bug report?!
Here is the topic I raised on this issue six months ago, conplete with logs:
http://forums.contribs.org/index.php?topic=29401.0The discussion went right over my head wrt forwarding and stateless sessions and stuff, but you may be able to extract something useful. All I know is that sometimes passing GRE from a PC, through an SME to a remote SME, *does* work about half the time. I just don't know what stops it working the other half of the time.
The VPN options seem to be stuck between a rock and a hard place:
1. Use Microsoft's PPTP, easy to set up on a PC or Mac, but requires GRE ports, which are essentially unreliable through an SME due to its special non-IP protocol. Score: one-nil to Windows.
2. Use IPSec, which is transported over standard TCP/IP ports, so reliable through an SME server, but requires a 20-step setup on MS Windows, involving a dozen security policy screens I never even knew existed in Windows XP until I tried to follow the steps. Score: one-nil to SME.
I am wondering, because PPTP was essentially designed for a single machine to negotiate a connection before exchanging IP information, whether an SME box will support only ONE machine in the internal network passing through protocol 47/GRE?
-- JJ