Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Arnt Karlsen <arnt@c2i.net>
To: netfilter@lists.netfilter.org
Subject: Re: PPTP through iptables firewall
Date: Fri, 7 Feb 2003 19:58:11 +0100	[thread overview]
Message-ID: <20030207195811.5aa9da41.arnt@c2i.net> (raw)
In-Reply-To: <E88493086664D511A1E4000103330E82027FE05C@mail.maconomy.dk>

On Fri, 7 Feb 2003 09:43:22 +0100, 
Niels Bach <NB@maconomy.dk> wrote in message 
<E88493086664D511A1E4000103330E82027FE05C@mail.maconomy.dk>:

> I have an MS PPTP server (win2k) behind a linux firewall (kernel
> 2.4.20 / iptables 1.2.7a) this does not work very well. You can only
> connect from one source at a time. Then there is a 10 minute (600
> seconds) timeout before the next connection from a different source
> can be made. If you come from a LAN that is NAT'ed to one IP address
> (the firewalls) then all these clients can connect simultaneously. So
> it is either one client with a public ip address or several clients
> sharing a public IP address. But once their is a connection (either
> type) everybody else is blocked out.


..we went with poptop servers instead, 2 (soon 3) for an isp 
business, to control access, trottle bandwidth and wrap 802.11 
traffic into tunnels, some of his too cheap nodes are limited 
256 connections, and the 257'th cause a reboot, and, he 
preferred poptop because of his wintendo 9x clients.  

..'http://poptop.org/', we use it on both public and private ip's.
 
> I have tried to patch the kernel (patch-o-matic-20030107) with the
> pptp-conntrack-nat.patch. With this patch the firewall is able to
> recognize the GRE protocol. This can be seen in /proc/net/ip_conntrack
> where the connections involving GRE has changed from UNKNOWN to GRE.
> But with this patch it is not possible to connect, now the windows
> client only reach"verifying username and password" and then times out.

..how do I patch-o-matic Red Hat's 2.4.18-24.8.0 rpm 
kernel source without impossible rejects?  Or, generate 
good old fashion vanilla style patches, so I can _see_ 
what the hell is going on in my boxes.

> Without the patch it is possible to connect to the server one at a
> time and wait 10 minutes before the next connection from a different
> location
> 
> With the patch it is not possible to connect at all.
> 
> I run Debian 3.0 (woody) Kernel 2.4.20 and iptables 1.2.7a with the
> patched version and 1.2.6a with the unpatched version of the kernel.
> 
> I have seen more people talking about this issue on the web, but no
> one seems to have at solution. 
> 
> regards Niels

..my problem is I don't know _why_ poptop works, but my (business) 
client tells me it _does_!?!?!?  And he went ahead and sold a box!

-- 
..med vennlig hilsen = with Kind Regards from Arnt... ;-)
...with a number of polar bear hunters in his ancestry...
  Scenarios always come in sets of three: 
  best case, worst case, and just in case.



  parent reply	other threads:[~2003-02-07 18:58 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-02-07  8:43 PPTP through iptables firewall Niels Bach
2003-02-07  9:28 ` Tomasz Wrona
2003-02-07 14:46   ` Lan traffic Monitoring tools Sundaram Ramasamy
2003-02-07 15:08     ` Aldo Lagana
2003-02-07 16:07     ` Paul Cousins
2003-02-07 16:14     ` Rowan Reid
2003-02-07 18:58 ` Arnt Karlsen [this message]
  -- strict thread matches above, loose matches on Subject: below --
2003-02-07 19:20 PPTP through iptables firewall Rob Sterenborg
2003-02-11 10:54 Niels Bach
2003-02-11 19:35 ` Arnt Karlsen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20030207195811.5aa9da41.arnt@c2i.net \
    --to=arnt@c2i.net \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox