Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PPTP and CARP

    Scheduled Pinned Locked Moved HA/CARP/VIPs
    8 Posts 5 Posters 4.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • U
      UnderCover
      last edited by

      is there a way I can enable PPTP and use the "virtual IP" (carp IP) so that if the primary goes down the vpn will kick over to the secondary?

      everytime i try to use the carp ip it syas no connection found on the VPN but if I specify the primary ip it connects…

      1 Reply Last reply Reply Quote 0
      • U
        UnderCover
        last edited by

        sorry to bump but any suggestions?

        1 Reply Last reply Reply Quote 0
        • D
          dhipo
          last edited by

          i am using with success CARP + Pptp

          all clients connect to CARP address with sucess.. when 1 server are down, or 2 servers up, no problems found.

          maybe i can help you on this

          Dhix Networks
          Everything Secure

          http://www.dhix.com.br

          1 Reply Last reply Reply Quote 0
          • B
            ben.suffolk
            last edited by

            Hi,

            You need to add 2 new rules,  allow TCP from any to VIP/1723 , and a GRE from any/any to VIP/any

            Both on the WAN interface.

            PPTP rules get added by default, but not to VIP addresses, only the WAN address, maybe this is a bug that needs fixing?

            Regards

            Ben

            1 Reply Last reply Reply Quote 0
            • U
              UnderCover
              last edited by

              thx this did the job

              1 Reply Last reply Reply Quote 0
              • A
                aaron
                last edited by

                I'm not sure that it's really a bug, because how would pfSense know that the VIP is intended for use with PPTP?  Although I also had this same problem when I first set up a PPTP to listen on a VIP, so I agree that we should make it more prominent.  Maybe sticky it (not quite sure if it's that common of a problem), but I'll look into adding it somewhere on the wiki.

                1 Reply Last reply Reply Quote 0
                • B
                  BenHead
                  last edited by

                  I think ideally the automatic firewall rule would be visible and/or editable, like NAT-created rules.

                  1 Reply Last reply Reply Quote 0
                  • B
                    ben.suffolk
                    last edited by

                    Is it really likely would you want to set PPTP up on the IP of the machine, and not the VIP?

                    I'm sure in pretty much every case if you set it up on a clustered machine its going to be on the VIP, or else you loose access when the machines failover.

                    Ben

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.