[SOLVED] Windows7 VPN clients behind Debian Gateway can not connect to Draytek VPN
Linux - ServerThis forum is for the discussion of Linux Software used in a server related context.
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Introduction to Linux - A Hands on Guide
This guide was created as an overview of the Linux Operating System, geared toward new users as an exploration tour and getting started guide, with exercises at the end of each chapter.
For more advanced trainees it can be a desktop reference, and a collection of the base knowledge needed to proceed with system and network administration. This book contains many real life examples derived from the author's experience as a Linux system and network administrator, trainer and consultant. They hope these examples will help you to get a better understanding of the Linux system and that you feel encouraged to try out things on your own.
Click Here to receive this Complete Guide absolutely free.
Windows7 VPN clients behind Debian Gateway can not connect to Draytek VPN
I am using Debian 6.05 with iptables & squid3 installed.
My Windows clients can't connect to Draytek VPN server which is located in another country with their built-in windows VPN clients. Sometimes they can connect but the Gateway configuration never changes.
The same VPN is working successfully outside my gateway.
This is a huge problem for me since Application Servers behind Gateway are using PPTP VPN for replications.
My network schema is below.
Internet--ZyXEL GIGABIT ROUTER--DEBIAN GW--Windows DHCP Server--Switch--AppServers, APs, Clients
I am using IPTables to block facebook and torrent traffic and Squid3 for URL and File type filtering.
There is nothing filtered about VPN, I tested with fresh installed Debian without Squid3 and iptables filtering rules. And I still couldn't connect.
These are the log entries from a different PPTP VPN Server which is also a Debian
Aug 31 23:16:10 (none) pptpd: CTRL: Client xxx.xxx.xxx.xxx control connection started
Aug 31 23:16:10 (none) pptpd: CTRL: Starting call (launching pppd, opening GRE)
Aug 31 23:16:10 (none) pppd: Plugin /usr/lib/pptpd/pptpd-logwtmp.so loaded.
Aug 31 23:16:10 (none) pppd: pppd 2.4.5 started by root, uid 0
Aug 31 23:16:10 (none) pppd: Using interface ppp0
Aug 31 23:16:10 (none) pppd: Connect: ppp0 <--> /dev/pts/2
Aug 31 23:16:10 (none) pptpd: GRE: Bad checksum from pppd.
Aug 31 23:16:40 (none) pppd: LCP: timeout sending Config-Requests
Aug 31 23:16:40 (none) pppd: Connection terminated.
Aug 31 23:16:40 (none) pppd: Modem hangup
Aug 31 23:16:40 (none) pppd: Exit.
Aug 31 23:16:40 (none) pptpd: GRE: read(fd=6,buffer=8058640,len=8196) from PTY failed: status = -1 error = Input/output error, usually caused by unexpected termination of pppd, check option syntax and pppd logs
Aug 31 23:16:40 (none) pptpd: CTRL: PTY read or GRE write failed (pty,gre)=(6,7)
Aug 31 23:16:40 (none) pptpd: CTRL: Reaping child PPP
Aug 31 23:16:40 (none) pptpd: CTRL: Client xxx.xxx.xxx.xxx control connection finished
VPN clients are giving 619 Error Codes.
How can I solve this problem?
Thanks in advance.
Last edited by neopandid; 08-31-2012 at 11:21 PM.
Reason: log information added.
Have you loaded the connection tracking modules for PPTP?
For the GRE part of PPTP to work properly behind a firewall, the PPTP conntrack module (nf_conntrack_pptp) must be loaded (or compiled into the kernel). If the connection is NATed, the PPTP NAT module (nf_nat_pptp) must be loaded as well.