Re: Help, I have some problem with LCP ConfReq
James Cameron <[email protected]>
| Newsgroups | gmane.network.poptop |
|---|---|
| Organization | Netrek Vanilla Server Dictator |
| Message-ID | <[email protected]> |
On Mon, Apr 11, 2011 at 03:52:13PM +0800, Benimaur Gao wrote: > Server Side: > > skyxen:~# tcpdump -ni eth0 host 121.0.29.193 and proto gre > tcpdump: verbose output suppressed, use -v or -vv for full protocol decode > listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes > 14:59:43.829782 IP 199.68.197.202 > 121.0.29.193: GREv1, call 59360, > seq 0, length 41: LCP, Conf-Request (0x01), id 1, length 27 > 14:59:44.014911 IP 121.0.29.193 > 199.68.197.202: GREv1, call 1536, > seq 1, length 36: LCP, Conf-Request (0x01), id 1, length 22 Positive proof that server is emitting GRE. The server understands the client IP is 121.0.29.193. > Client(from my debian): > skyshouter:/home/benimaur# tcpdump -ni eth1 proto gre and host 199.68.197.202 > tcpdump: verbose output suppressed, use -v or -vv for full protocol decode > listening on eth1, link-type EN10MB (Ethernet), capture size 65535 bytes > 15:06:56.957177 IP 10.16.2.60 > 199.68.197.202: GREv1, call 1536, seq > 1, length 36: LCP, Conf-Request (0x01), id 1, length 22 > 15:06:59.581653 IP 10.16.2.60 > 199.68.197.202: GREv1, call 1536, seq > 2, length 36: LCP, Conf-Request (0x01), id 1, length 22 > 15:07:02.581648 IP 10.16.2.60 > 199.68.197.202: GREv1, call 1536, seq > 3, length 36: LCP, Conf-Request (0x01), id 1, length 22 Positive proof that network is not supplying any of the server GRE packets to the client. Positive proof that the client is behind a NAT router of some sort; since the IP address is in 10/8 range. This means the NAT router is responsible for readdressing the packets. > Client(created by wireshark): > > skyshouter:/home/benimaur/share/incoming# tcpdump -r temp.pcap host > 199.68.197.202 and proto gre > reading from file temp.pcap, link-type EN10MB (Ethernet) > 15:29:54.390057 IP 10.16.2.128 > 199.68.197.202: GREv1, call 1792, seq > 0, length 37: LCP, Conf-Request (0x01), id 0, length 23 > 15:29:54.578682 IP 199.68.197.202 > 10.16.2.128: GREv1, call 16384, > seq 1, ack 0, length 27: LCP, Conf-Reject (0x04), id 0, length 9 Positive proof that the NAT router is capable of readdressing the packets. Theory: the NAT router only supports Windows PPTP. > It seems that GRE packes must be dropped somewhere, and is there any > means to solve this problem? No, not unless you can fix the NAT router. You might use OpenVPN instead, since it does not require such excellence and processing by a NAT router. To identify the NAT router, it is the device that has the IP address 121.0.29.193. -- James Cameron http://quozl.linux.org.au/ ------------------------------------------------------------------------------ Xperia(TM) PLAY It's a major breakthrough. An authentic gaming smartphone on the nation's most reliable network. And it wants your games. http://p.sf.net/sfu/verizon-sfdev