PPTP VPN and SQUIDGUARD not working



  • Hi,
    2.0-BETA4 (i386)
    built on Wed Aug 18

    when i enable PPTP VPN squidguard stops with web filtering, when i disable PPTP filtering works again.

    can you check that guys?

    thanks


  • Rebel Alliance Developer Netgate

    Not nearly enough detail there. Any errors in the logs? Notices in the gui? Does the service stop running?

    What are the contents of /tmp/rules.debug when it works and when it doesn't?



  • system services shows that services are running (squid and squidguard),
    no notices in gui
    and system logs show this
    Aug 24 07:21:21 mpd: process 49842 started, version 4.4.1 (root@FreeBSD_8.0_pfSense_2.0-snaps.pfsense.org 12:40 18-Aug-2010)
    Aug 24 07:21:21 mpd: Label 'startup' not found
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt0] using interface pptpd0
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt1] using interface pptpd1
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt2] using interface pptpd2
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt3] using interface pptpd3
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt4] using interface pptpd4
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt5] using interface pptpd5
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt6] using interface pptpd6
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt7] using interface pptpd7
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt8] using interface pptpd8
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt9] using interface pptpd9
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt10] using interface pptpd10
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt11] using interface pptpd11
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt12] using interface pptpd12
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt13] using interface pptpd13
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt14] using interface pptpd14
    Aug 24 07:21:21 mpd: PPTP: waiting for connection on 0.0.0.0
    Aug 24 07:21:21 mpd: [pt15] using interface pptpd15
    Aug 24 07:21:24 check_reload_status: syncing firewall
    Aug 24 07:21:30 php: : The command '/sbin/pfctl -nf /tmp/rules.test.packages' returned exit code '1', the output was '/tmp/rules.test.packages:6: macro 'pptp' not defined /tmp/rules.test.packages:6: syntax error'
    Aug 24 07:21:30 php: : There was an error while parsing the package filter rules for /usr/local/pkg/squid.inc.
    Aug 24 07:21:31 php: : The command '/sbin/pfctl -nf /tmp/rules.test.packages' returned exit code '1', the output was '/tmp/rules.test.packages:13: macro 'pptp' not defined /tmp/rules.test.packages:13: syntax error'
    Aug 24 07:21:31 php: : There was an error while parsing the package filter rules for /usr/local/pkg/squid.inc.

    restating squidguard service does not help.

    thanks



  • just asking, is anyone up to get this fix?
    thanks



  • any updates ?
    thanks



  • Month ago, i asked for this problem, no one answered, even try, since this is not working on 1.2.3. and it is not working on 2.0, it becomes very frustrating.
    Can someone please tell me is someone working on this?
    thanks



  • It looks to me this request is still outstanding:

    @jimp:

    What are the contents of /tmp/rules.debug when it works and when it doesn't?



  • this is with PPTP VPN off

    this is copy paste only of vpn part, i dont think you need firewall, nat, gateway… data?
    also there is nothing related to squid in this file
    ,,,
    ,,,
    ,,,

    VPN Rules

    package manager late specific hook

    anchor "packagelate"

    anchor "tftp-proxy/*"

    anchor "limitingesr"

    uPnPd

    anchor "miniupnpd"

    Setup squid pass rules for proxy

    pass in quick on re0 proto tcp from any to !(re0) port 80 flags S/SA keep state
    pass in quick on re0 proto tcp from any to !(re0) port 3128 flags S/SA keep state

    Setup squid pass rules for proxy

    pass in quick on re1 proto tcp from any to !(re1) port 80 flags S/SA keep state
    pass in quick on re1 proto tcp from any to !(re1) port 3128 flags S/SA keep state

    Setup squid pass rules for proxy

    pass in quick on re2 proto tcp from any to !(re2) port 80 flags S/SA keep state
    pass in quick on re2 proto tcp from any to !(re2) port 3128 flags S/SA keep state

    this ia with PPTP VPN on

    VPN Rules

    package manager late specific hook

    anchor "packagelate"

    anchor "tftp-proxy/*"

    anchor "limitingesr"

    uPnPd

    anchor "miniupnpd"


  • Rebel Alliance Developer Netgate

    I asked for the whole file, and yes, I need the whole file. The VPN part, and the headers, etc, where the PPTP things are defined among others. We can't help unless we get all relevant information.

    Save them as .txt files and attach them to the thread (or the open ticket about this)



  • OK, here is *.txt file…
    wan, and wan gw IP edited with ---.---.---.---

    [VPN ON.txt](/public/imported_attachments/1/VPN ON.txt)
    [VPN OFF.txt](/public/imported_attachments/1/VPN OFF.txt)



  • 6 days passed, and no feedback.
    im just asking is anyone up to this, any news? Or is it best way just to seat back and wait?

    thanks


  • Rebel Alliance Developer Netgate

    Should be fixed in new snapshots made after this post (there may be one in progress right now that would not include the fixes), so by tomorrow AM there should be a snap that works.



  • thank you for your prompt reply, will try and leave feedback



  • well i said i will leave feedback…

    i try to upgrade my 1.2.3 installation since on test machine squidguard and pptp vpn works. (everything left by default)
    After upgrade, PPTP VPN submenu freezes and it is imposible to change anything, and upgrade transfer all values (like radius port, ip address etc) as number 1.

    Than i tried to restore configuration from old backup from 1.2.3 verson, and it didnt work well.
    so i decide to go for fresh install...

    I have configure everything and it works, except :) when you touch WAN firewall rules VPN does not work after that.

    So you can set some random rule, and then delete it and VPN is not working any more.
    also i tried to add firewall rule to wan interface to pass any source to ip adress of pptp vpn server by port 1723 no luck.
    Also, on version 1.2.3 in wan interface firewall on single rule to block all pptp traffic was able to pass through, on pfs 2.0 it cant.
    On client computer when trying to connect to VPN it hangs on, and it cant come to part verifying username and password.

    is there some new configuration for pptp in pfs 2.0, or it still need small fix?


  • Rebel Alliance Developer Netgate

    Those issues are unrelated to this thread, you'd be better off starting a new thread with a relevant subject to draw more attention. I haven't used PPTP on 2.0 myself much, some others have said it wasn't working, some said it was. Others may have tips.



  • also there is no PPTP VPN events in log ?
    and as i said, it works until single firewall rule is added to WAN interface :(
    after that, even if you delete all rules it is not working any more.

    I know that this issues are not related any more with first problem (VPN crashes squidguard), but can we end this story with PPTP to end? or i have to open new topic in VPN or firewall ?

    And, thank you for all your help



  • update to latest snapshot, reboot, add rule to firewall for wan interface to - pass port 1723 from any to wan-, and now works, silly, version 1.2.3 didnt need that.
    Now, just to fix logging, it does not work.
    Thanks for all help


  • Rebel Alliance Developer Netgate

    I thought PPTP logs were under the PPP tab, you just need to press the PPTP button there. I may be wrong though, there's an open ticket for the logging.

    Again though, a new thread with a more relevant subject would catch more eyes.

    EDIT: I see you started a new thread, nevermind. :-)


Log in to reply