Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot Connect PPTP VPN

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    36 Posts 14 Posters 19.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Juve
      last edited by

      Ok so it seems to be a state tracking problem ?
      When you watch the logs during a connection attempt (tcpdump -i pflog0 -ttt -n) you can see GRE responses from the outside server being blocked by pf.

      1 Reply Last reply Reply Quote 0
      • J
        Juve
        last edited by

        No news neither a clue about this issue ?

        1 Reply Last reply Reply Quote 0
        • E
          eri--
          last edited by

          Wait for a new image to get built, just committed the fix.
          https://rcs.pfsense.org/projects/pfsense-tools/repos/mainline/commits/1c33e5128463d84dcedb71c9480a126dd8a6466e

          1 Reply Last reply Reply Quote 0
          • J
            Juve
            last edited by

            will try it asap.
            Thanks Ermal.

            1 Reply Last reply Reply Quote 0
            • T
              toomeek
              last edited by

              Same issue here.
              Tried to use it with Win2k8 TMG.
              TMG's gateway is pfSense LAN IP (this is important! without this forwarding doesn't work)
              Seems it even don't try to connect, just refusing connection with CLOSED:SYN_SENT.
              Just ignoring firewall rules… or I have missed something in pfSense firewall?
              Check screenshots attached.

              EDIT: sorry for information missed: tested on pfSense-2.0-BETA4-20101116-1840-i386.iso
              EDIT: Thanks for fix for Ticket #989. Will try this as soon new snapshot will be available.

              pfsense_pptp_redirect.png
              pfsense_pptp_redirect.png_thumb
              pfsense_PPTP_firewall.png
              pfsense_PPTP_firewall.png_thumb
              pfsense_ppt_diagnostic.png
              pfsense_ppt_diagnostic.png_thumb
              pfSense_Windows_TMG_rule.png
              pfSense_Windows_TMG_rule.png_thumb

              1 Reply Last reply Reply Quote 0
              • E
                eri--
                last edited by

                You do not need the gre allowance with latest snaphots.
                Your problem is that you do not need to specify the gateway in firewall rules.

                1 Reply Last reply Reply Quote 0
                • E
                  erialor
                  last edited by

                  Confirming that outgoing PPTP VPN now works w/o incoming GRE-rule - thanks :D

                  1 Reply Last reply Reply Quote 0
                  • J
                    Juve
                    last edited by

                    Confirming this too.

                    Thanks

                    1 Reply Last reply Reply Quote 0
                    • D
                      Digital
                      last edited by

                      Confirming that PPTP limitations are gone for good :)

                      Thanks!

                      ermal: just curious - will there be an OpenBSD pf patch in the future?

                      1 Reply Last reply Reply Quote 0
                      • E
                        eri--
                        last edited by

                        You can try yourself.
                        From my side i am done with OpenBSD folks doing politics.

                        1 Reply Last reply Reply Quote 0
                        • J
                          Juve
                          last edited by

                          nice reply Ermal  ;)

                          1 Reply Last reply Reply Quote 0
                          • S
                            sparc317
                            last edited by

                            confirmed as well on 2.0-BETA4 (i386)
                            built on Wed Nov 24 19:45:12 EST 2010

                            well done guys, thanks so much for this

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.