PPTP Passthrough

  • One of our clients uses a PPTP VPN.
    We are unable to access this from within our network, if we use a secondary router we are able to access it.
    I have added the following rules in both LAN and WAN.
    GRE * * * * * None
    TCP * * * 1723 * None

    However PPTP Outbound still fails.

  • LAYER 8 Global Moderator

    I would work on getting your client up to speed on what is actual secure vpn in this day and age ;)  PPTP has been dead for years!

    What version of pfsense are you using?

    Why would you need any rules on wan if your outbound to their pptp server?  I am pretty sure they removed the PPTP passthru features then they removed PPTP.. If I recall when pptp goes through a nat the GRE portion there is a call id added to the headers.. Been many years since I had to work with that crap they call PPTP ;)

    Good luck I guess.. If was a client of mine would be selling them on how bad pptp is and why they need to update to something current ;)

  • We are using 2.1.5-RELEASE (i386)

    From all the research that I have done, everyone says that it is a GRE Firewall rule that is blocking it.
    I added the rule to both the LAN and WAN to be sure and not luck.

    We swapped out the router with a Cisco unit to test and were able to connect without an issue.

  • LAYER 8 Global Moderator

    2.1.5 still had pptp stuff.. So not only do you use OLD vpn protocols, you also use OLD pfsense ;)  Current pfsense is 2.3.4..

    Your not running pptp itself on pfsense are you?  There were many issues with that and passthru if I recall.  I thought the older versions that had pptp enabled on them had some pptp passthru settings that could be enabled… I would have to fire up such an old version to take a look.

Log in to reply