LinuxQuestions.org
Visit the LQ Articles and Editorials section
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
Search this Thread
Old 11-03-2008, 05:47 PM   #1
Jiggs
LQ Newbie
 
Registered: Sep 2004
Distribution: SuSE 10.0
Posts: 17

Rep: Reputation: 0
Kubuntu / Iptables / Windows VPN Issue


Hi,

I'm having problems with my laptop connecting through my linux router to my corporate VPN.

My setup is as follows.
Cable Modem -> (eht1) Linux Router (eth3) -> SWITCH -> Rest of House.
One of the connections in the house has a WRT54G wireless router on it.

Everything works great except connecting through the linux router to the VPN.

It should be noted, I just replaced the Linux router for an older Ubuntu machine, and VPN worked fine. I'm just missing something, but I'm not sure what.

My laptop connecting wirelessly can connect to anything on the internet. However, when I try to connect to a Windows VPN server, it fails. It reaches the "Verifying Username and Password" stage and hangs.

The linux router is running Kubunu 8.04 64-Bit, running Firestarter on Iptables.

I have added this to /etc/firestarter/user-pre as indicated online:
# Forward PPTP VPN client traffic
$IPT -A FORWARD -i $IF -o $INIF -p tcp --dport 1723 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
$IPT -A FORWARD -i $IF -o $INIF -p 47 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
$IPT -A FORWARD -i $INIF -o $IF -p 47 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT

PLEASE help!!!

Jiggs
 
Old 11-03-2008, 06:00 PM   #2
Jiggs
LQ Newbie
 
Registered: Sep 2004
Distribution: SuSE 10.0
Posts: 17

Original Poster
Rep: Reputation: 0
Ok, well I feel slightly silly, but maybe this will help someone else.

Firstly, I checked DMESG... and it held the key.

It was showing packets from eth3 (my lan) to eth1 (internet) destination port 1723 being dropped. Which, shouldn't have happened as I had an ALLOW ALL on that subnet (lan).

Example:
[ 725.368096] DROPPED IN=eth3 OUT=eth1 SRC=192.168.100.xxx DST=65.xxx.xxx.xxx LEN=48 TOS=0x08 PREC=0x60 TTL=126 ID=19816 DF PROTO=TCP SPT=4411 DPT=1723 SEQ=583123285 ACK=0 WINDOW=16384 RES=0x00 SYN URGP=0 OPT ()

I added an exception to allow port 1723 where source = LAN, and it worked.

Jiggs
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
windows vpn and iptables Ammad Linux - Networking 3 07-12-2007 06:46 AM
Setting up VPN in Kubuntu 6.10 sociopathicsolicitor Linux - Networking 1 02-23-2007 06:27 AM
Configure Linux VPN Server for a Windows VPN Client xbaez Linux - Networking 4 04-28-2006 03:29 PM
Linux VPN Software - How to Connect to a Windows VPN wfernley Linux - Software 2 02-07-2006 09:40 AM
iptables and Windows PPTP VPN jbrandis Linux - Security 2 12-17-2001 04:20 AM


All times are GMT -5. The time now is 11:32 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration