• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

PPTP and CARP

HA/CARP/VIPs
5
8
4.7k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • U
    UnderCover
    last edited by Jan 31, 2008, 2:17 PM

    is there a way I can enable PPTP and use the "virtual IP" (carp IP) so that if the primary goes down the vpn will kick over to the secondary?

    everytime i try to use the carp ip it syas no connection found on the VPN but if I specify the primary ip it connects…

    1 Reply Last reply Reply Quote 0
    • U
      UnderCover
      last edited by Feb 1, 2008, 9:44 PM

      sorry to bump but any suggestions?

      1 Reply Last reply Reply Quote 0
      • D
        dhipo
        last edited by Feb 9, 2008, 2:52 PM

        i am using with success CARP + Pptp

        all clients connect to CARP address with sucess.. when 1 server are down, or 2 servers up, no problems found.

        maybe i can help you on this

        Dhix Networks
        Everything Secure

        http://www.dhix.com.br

        1 Reply Last reply Reply Quote 0
        • B
          ben.suffolk
          last edited by Feb 9, 2008, 10:50 PM

          Hi,

          You need to add 2 new rules,  allow TCP from any to VIP/1723 , and a GRE from any/any to VIP/any

          Both on the WAN interface.

          PPTP rules get added by default, but not to VIP addresses, only the WAN address, maybe this is a bug that needs fixing?

          Regards

          Ben

          1 Reply Last reply Reply Quote 0
          • U
            UnderCover
            last edited by Feb 21, 2008, 3:26 PM

            thx this did the job

            1 Reply Last reply Reply Quote 0
            • A
              aaron
              last edited by Feb 22, 2008, 2:24 PM

              I'm not sure that it's really a bug, because how would pfSense know that the VIP is intended for use with PPTP?  Although I also had this same problem when I first set up a PPTP to listen on a VIP, so I agree that we should make it more prominent.  Maybe sticky it (not quite sure if it's that common of a problem), but I'll look into adding it somewhere on the wiki.

              1 Reply Last reply Reply Quote 0
              • B
                BenHead
                last edited by Mar 10, 2008, 7:09 PM

                I think ideally the automatic firewall rule would be visible and/or editable, like NAT-created rules.

                1 Reply Last reply Reply Quote 0
                • B
                  ben.suffolk
                  last edited by Mar 10, 2008, 8:14 PM

                  Is it really likely would you want to set PPTP up on the IP of the machine, and not the VIP?

                  I'm sure in pretty much every case if you set it up on a clustered machine its going to be on the VIP, or else you loose access when the machines failover.

                  Ben

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.