stefaniobrunhara
(usa CentOS)
Enviado em 23/10/2014 - 09:28h
Estou usando como base o link abaixo para criar uma vpn pptpd
http://www.vivaolinux.com.br/artigo/VPN-PPTP-Instalacao-entre-estacoes-Windows-Dispositivos-com-Andr...
Criei um cenário simples com PAP somente para ver o funcionamento.
Estou com o seguinte problema, minha conexão disca autentica conecta minha interface recebe o IP 10.10.1.1 porém depois de alguns segundos a conexão cai.
#### módulos carregados ####
# lsmod|grep ip_gre
ip_gre 12680 0
# lsmod|grep ppp
ppp_deflate 3562 0
zlib_deflate 19141 1 ppp_deflate
ppp_async 6630 0
crc_ccitt 1337 1 ppp_async
ppp_mppe 5388 0
ppp_generic 21042 3 ppp_deflate,ppp_async,ppp_mppe
slhc 5329 1 ppp_generic
#### Configuração PPTPD ####
# cat /etc/pptpd.conf
option /etc/ppp/options.pptpd
logwtmp
debug
localip 10.10.1.253
remoteip 10.10.1.1-5
# cat /etc/ppp/options.pptpd
name pptpd
require-pap
require-chap
require-mschap
#require-mschap-v2
#require-mppe-128
#ms-dns 8.8.8.8
#ms-dns 8.8.4.4
#ms-wins 192.168.0.210
debug
lock
nobsdcomp
nologfd
proxyarp
#novj
#novjccomp
O que esta comentado nas linhas acima e a configuração atual.
# cat /etc/ppp/pap-secrets
# Secrets for authentication using PAP
# client server secret IP adresses
teste01 pptpd 123456 *
[root@ns0 stf]# cat /etc/ppp/chap-secrets
# Secrets for authentication using CHAP
# client server secret IP addresses
teste01 pptpd 123456 *
#### discador do Windows 7 ####
Tipo de VPN = Protocolo de túnel ponto a ponto
Criptografia de dados = Criptografia opcional (conectar mesmo sem criptografia)
Permitir protocolos = Senha não criptografa (PAP)
#### Firewall somente o básico para testes ####
Tanto no ponta A como no ponto B a internet e compartilhada com Linux, ambas as pontas estão com este firewall básico.
[root@ns0 tmp]# iptables -nL
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT 47 -- 0.0.0.0/0 0.0.0.0/0
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT 47 -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
[root@ns0 tmp]#
[root@ns0 tmp]#
[root@ns0 tmp]# iptables -nL -t nat
Chain PREROUTING (policy ACCEPT)
target prot opt source destination
Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
ACCEPT 47 -- 0.0.0.0/0 0.0.0.0/0
MASQUERADE all -- 0.0.0.0/0 0.0.0.0/0
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
#### Log do erro ####
Oct 23 09:00:36 ns0 pptpd[624]: GRE: xmit failed from decaps_hdlc: Network is unreachable
Oct 23 09:00:36 ns0 pptpd[624]: CTRL: PTY read or GRE write failed (pty,gre)=(6,7)
#### Log completo ####
Oct 23 09:00:21 ns0 pptpd[624]: CTRL: Client 187.20.32.211 control connection started
Oct 23 09:00:21 ns0 pptpd[624]: CTRL: Starting call (launching pppd, opening GRE)
Oct 23 09:00:21 ns0 pppd[625]: Plugin /usr/lib/pptpd/pptpd-logwtmp.so loaded.
Oct 23 09:00:21 ns0 pppd[625]: pptpd-logwtmp: $Version$
Oct 23 09:00:21 ns0 pppd[625]: pppd 2.4.5 started by stf, uid 0
Oct 23 09:00:21 ns0 pppd[625]: Using interface ppp0
Oct 23 09:00:21 ns0 pppd[625]: Connect: ppp0 <--> /dev/pts/0
Oct 23 09:00:32 ns0 pppd[625]: PAP peer authentication succeeded for regional01
Oct 23 09:00:32 ns0 pppd[625]: peer from calling number 187.20.32.211 authorized
Oct 23 09:00:36 ns0 pppd[625]: Cannot determine ethernet address for proxy ARP
Oct 23 09:00:36 ns0 pppd[625]: local IP address 10.10.1.253
Oct 23 09:00:36 ns0 pppd[625]: remote IP address 10.10.1.1
Oct 23 09:00:36 ns0 pppd[625]: pptpd-logwtmp.so ip-up ppp0 teste01 187.20.32.211
Oct 23 09:00:36 ns0 pptpd[624]: GRE: xmit failed from decaps_hdlc: Network is unreachable
Oct 23 09:00:36 ns0 pptpd[624]: CTRL: PTY read or GRE write failed (pty,gre)=(6,7)
Oct 23 09:00:36 ns0 pppd[625]: Modem hangup
Oct 23 09:00:36 ns0 pppd[625]: pptpd-logwtmp.so ip-down ppp0
Oct 23 09:00:36 ns0 pppd[625]: Connect time 0.0 minutes.
Oct 23 09:00:36 ns0 pppd[625]: Sent 80 bytes, received 340 bytes.
Oct 23 09:00:36 ns0 pppd[625]: Connection terminated.
Oct 23 09:00:41 ns0 pppd[625]: Exit.
Oct 23 09:00:41 ns0 pptpd[624]: CTRL: Client 187.20.32.211 control connection finished