All of lore.kernel.org
 help / color / mirror / Atom feed
* PPTP NAT module
@ 2003-12-09 23:03 Joshua Jackson
  2003-12-11 15:57 ` Oleg Savostyanov
  0 siblings, 1 reply; 7+ messages in thread
From: Joshua Jackson @ 2003-12-09 23:03 UTC (permalink / raw)
  To: netfilter

I know there have been a pile of questions about this module in the past, but 
I can't seem to find any responses about the behaviour I am seeing.

I am currently running a 2.4.23 kernel with the lastest officially released 
POM patches applied to it. The network being protected by the firewall is 
providing NAT for the hosts behind it. If the ip_nat_pptp module is loaded, 
none of the protected clients can establish an outbound PPTP session. If the 
conntrack modules are removed, a single session can be established (as would 
be expected).

The remote PPTP server log shows the initial TCP connection, but never sees 
any GRE traffic from the connecting host.

I have seen posts about the local NAT kernel option, I have tried it both ways 
with the same results. If there are any kernel settings in particular that I 
may be missing, please let me know.

My iptables firewall rules include a default policy of DROP for INPUT and 
FORWARD, ACCEPT for OUTPUT. The first line in the rules includes an ACCEPT 
for the INPUT chain for established and related connection. There is also a 
rule allowing any traffic for all protocols to any host which originates from 
the protected network on the internal interface.

-- 
Joshua Jackson
Vortech Consulting
http://www.vortech.net



^ permalink raw reply	[flat|nested] 7+ messages in thread
* PPTP Nat Module
@ 2003-12-10  2:39 Joshua Jackson
  2003-12-10  3:24 ` Philip Craig
  0 siblings, 1 reply; 7+ messages in thread
From: Joshua Jackson @ 2003-12-10  2:39 UTC (permalink / raw)
  To: netfilter

I know there have been a pile of questions about this module in the past, but 
I can't seem to find any responses about the behaviour I am seeing.

I am currently running a 2.4.23 kernel with the lastest officially released 
POM patches applied to it. The network being protected by the firewall is 
providing NAT for the hosts behind it. If the ip_nat_pptp module is loaded, 
none of the protected clients can establish an outbound PPTP session. If the 
conntrack modules are removed, a single session can be established (as would 
be expected).

The remote PPTP server log shows the initial TCP connection, but never sees 
any GRE traffic from the connecting host.

I have seen posts about the local NAT kernel option, I have tried it both ways 
with the same results. If there are any kernel settings in particular that I 
may be missing, please let me know.

My iptables firewall rules include a default policy of DROP for INPUT and 
FORWARD, ACCEPT for OUTPUT. The first line in the rules includes an ACCEPT 
for the INPUT chain for established and related connection. There is also a 
rule allowing any traffic for all protocols to any host which originates from 
the protected network on the internal interface.

-- 
Joshua Jackson
Vortech Consulting
http://www.vortech.net



^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2003-12-20  4:14 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-09 23:03 PPTP NAT module Joshua Jackson
2003-12-11 15:57 ` Oleg Savostyanov
2003-12-11 16:49   ` Joshua Jackson
2003-12-20  4:14   ` Joshua Jackson
  -- strict thread matches above, loose matches on Subject: below --
2003-12-10  2:39 PPTP Nat Module Joshua Jackson
2003-12-10  3:24 ` Philip Craig
2003-12-10 18:17   ` Joshua Jackson

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.