Linux Netfilter discussions
 help / color / mirror / Atom feed
* pptp patch
@ 2003-06-18 13:27 Hill, John
  2003-06-19 16:18 ` Rowan Reid
  2003-06-20  8:43 ` Philip Craig
  0 siblings, 2 replies; 6+ messages in thread
From: Hill, John @ 2003-06-18 13:27 UTC (permalink / raw)
  To: 'netfilter@lists.netfilter.org'

For the record netfilter is a terrific tool. I am grateful for the time and
hard work given by the netfilter team.


I have kernel 2.4.21 netfilter - latest cvs.

Built netfilter for extra added pptp support.

Recompiled kernel -- netfilter.

I have a win2000 pptp server behind a Linux firewall

Dnat gre and port 1723 to the pptp server.

I had 3 VPN connections working. When one closed the connection the kernel
panicked and died. I could not recover the error message. I was forced to
power off.


I have used 2.4.19 with Brian Kuschak's 2.4.19 pptp patch without problems.
He no longer supports the patch. I was hoping to upgrade the kernel.
Unfortunately the 2.4.19 patch will not work on 2.4.21 and the pptp
netfilter patch will not work for me. I had to roll back to 2.4.19.

I have several firewall installations and need PPTP and the ability to keep
kernels current.

Has anyone looked at Brian's code to see if it is practical to be
incorporated by the netfilter team? 

Any help would be appreciated.


--John Hill








^ permalink raw reply	[flat|nested] 6+ messages in thread
* re: pptp patch
@ 2003-06-19 16:19 Gary Cote
  2003-06-19 16:32 ` Rowan Reid
  0 siblings, 1 reply; 6+ messages in thread
From: Gary Cote @ 2003-06-19 16:19 UTC (permalink / raw)
  To: netfilter

John,

I also need to to route pptp traffic through a box with 
recent kernel revisions (2.4.20-18.7 for me at the moment). 
The linux box is neither the pptp client nor server. It's 
just a router/NAT. Would you be so kind as to forward 
anything you might find out over to me? Once I know your
address, I'll do the same.

(sorry for the "me too" post on the list, but I subscribed
 to the group after your posting, and the archive masks out 
 email addresses.)

A couple questions:

. Am I correct in understanding that there are two pptp
  patches out there? One against the latest netfilter
  sources, and the John Hardin/Brian Kushak patch against
  earlier revisions?
  . Is the first one the patch-o-matic extra/pptp-conntrack-nat.patch?

. You said Brian Kushak's 2.4.19 patch won't work against 
  2.4.21. Do you simply mean that patch reported errors, 
  or have you looked into what it would take to port the
  patch to recent kernels? I've taken a quick look through
  it and saw the code has been redesigned in some spots,
  so it's not a simple cut-and-paste job. If it's already
  known to be a lost cause, then I won't waste any more time
  looking at it.

. Your post said you built 2.4.21 netfilter with pptp support.
  I guess this refers back to my first question. Are you
  referring to the pptp-conntrack-nat.patch?

Once I get my head screwed on straight about all this stuff,
and figure out what ground's already been covered, maybe we
can figure out how to get it to work for both of us.

thanks





^ permalink raw reply	[flat|nested] 6+ messages in thread
* pptp patch
@ 2003-10-15 11:29 Patrick Mauritz
  0 siblings, 0 replies; 6+ messages in thread
From: Patrick Mauritz @ 2003-10-15 11:29 UTC (permalink / raw)
  To: netfilter

hello,

I have a problem with the pptp patch from latest p-o-m, trying to
forward external pptp clients to a firewalled pptp server (win2k server).

clients <-> router <-> win2k server


iptables setup on router:

ip_{nat,conntrack}_{proto_gre,pptp} are loaded,
1723 is DNATed from external to the server
MASQUERADE is any to any

when trying to connect to the server, the connection is dropped after 115 to 119 seconds.

the connection lasts longer when I DNAT GRE protocol manually (and withou the pptp helpers), though that obviously only works for one user at a time.


I have no idea what further information I could provide, but I'll provide everything asked for. please Cc: as I'm not on the list.

TIA,
patrick mauritz


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-10-15 11:29 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-06-18 13:27 pptp patch Hill, John
2003-06-19 16:18 ` Rowan Reid
2003-06-20  8:43 ` Philip Craig
  -- strict thread matches above, loose matches on Subject: below --
2003-06-19 16:19 Gary Cote
2003-06-19 16:32 ` Rowan Reid
2003-10-15 11:29 Patrick Mauritz

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox