From owner-freebsd-net@FreeBSD.ORG Wed Mar 17 15:35:51 2004 Return-Path: Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4E94D16A4CE for ; Wed, 17 Mar 2004 15:35:51 -0800 (PST) Received: from horse.lucky.net (horse.carrier.kiev.ua [193.193.193.118]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3340A43D1F for ; Wed, 17 Mar 2004 15:35:49 -0800 (PST) (envelope-from news+freebsd-arts@news1.lucky.net) Received: from horse.lucky.net (news@localhost) by horse.lucky.net (8.11.6p2/8.11.6) with ESMTP id i2HNZjs58251 for ; Thu, 18 Mar 2004 01:35:45 +0200 (EET) (envelope-from news+freebsd-arts@news1.lucky.net) X-Authentication-Warning: horse.lucky.net: news owned process doing -bs To: freebsd-net@freebsd.org From: Alexander Motin Date: Wed, 17 Mar 2004 19:28:20 +0200 Organization: Alkar Teleport News Server Message-ID: References: <20040314091814.79495.qmail@istanbul.enderunix.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit X-Trace: pandora.alkar.net 1079544501 92731 212.86.226.11 (17 Mar 2004 17:28:21 GMT) User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.6) Gecko/20040119 X-Accept-Language: ru, en-us, en In-Reply-To: <20040314091814.79495.qmail@istanbul.enderunix.org> Sender: Alkar Teleport News Subsystem X-Verify-Sender: verified Subject: Re: mpd lcp question X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 17 Mar 2004 23:35:51 -0000 Hi Omer Faruk Sen wrote: > Hi, > I have set up an mpd server. But there is a problem. When I try to > connect with my home pc logs are generated like this: > ------------------------------------------------------ > [pptp] LCP: state change Req-Sent --> Ack-Sent > [pptp] LCP: SendConfigReq #2 > ACFCOMP > PROTOCOMP > MRU 1500 > MAGICNUM d3dbc780 > AUTHPROTO CHAP MSOFTv2 > MP MRRU 1600 > MP SHORTSEQ > ENDPOINTDISC [802.1] 00 90 27 d6 1c 0b > [pptp] LCP: rec'd Configure Reject #2 link 0 (Ack-Sent) > MP MRRU 1600 > MP SHORTSEQ > ENDPOINTDISC [802.1] 00 90 27 d6 1c 0b > [pptp] LCP: SendConfigReq #3 > ACFCOMP > PROTOCOMP > MRU 1500 > MAGICNUM d3dbc780 > AUTHPROTO CHAP MSOFTv2 > [pptp] LCP: rec'd Configure Ack #3 link 0 (Ack-Sent) > ACFCOMP > PROTOCOMP > MRU 1500 > MAGICNUM d3dbc780 > AUTHPROTO CHAP MSOFTv2 > [pptp] LCP: state change Ack-Sent --> Opened > ------------------------------------------------- > As you see from above and below (which is a partial copy of above) > [pptp] LCP: rec'd Configure Reject #2 link 0 (Ack-Sent) > MP MRRU 1600 > MP SHORTSEQ > ENDPOINTDISC [802.1] 00 90 27 d6 1c 0b > As far as I understand "mp mrru 1600", "mp shortseq" and "endpoint ..." > capabilities are rejected by mpd server. My windowsXP client sends > connection request with removing those capabilities and vpn connection > is established perfectly.. > But some XP and most Windows2k clients insists on those capabilities > rejected by mpd server thus connection is no established with an LCP error. > Is there a workaround or a way to enable "mp mrru 1600", "mp shortseq" > and "endpoint ..." properties on mpd server? Add set bundle enable multilink into your config file and mpd will support that options. > My configuration is like this: > -----mpd.conf----------- > default: > load pptp > > pptp: > new -i ng0 pptp pptp > set iface disable on-demand > set iface enable proxy-arp > set iface idle 1800 > set iface enable tcpmssfix > # set bundle enable multilink > # enable TCP-Wrapper (hosts_access(5)) to block unfriendly clients > # set bundle enable tcp-wrapper > # use RADIUS servers > # load radius > set link yes acfcomp protocomp > #set iface route default > set iface route 10.0.0.0/22 > set link no pap chap > set link enable chap > set link keep-alive 10 60 > set link mtu 1460 > set link mtu 1500 > set ipcp yes vjcomp > set ipcp ranges 10.0.0.26/32 10.0.0.54/32 > #set ipcp dns 192.168.1.3 > # The five lines below enable Microsoft Point-to-Point encryption > # (MPPE) using the ng_mppc(8) netgraph node type. > # > set bundle enable compression > set ccp yes mppc > set ccp yes mpp-e40 > set ccp yes mpp-e128 > set ccp yes mpp-stateless > -----------mpd.conf------------ > > -----mpd.links------- > pptp: > set link type pptp > set pptp self SERVER_IP > set pptp enable incoming > set pptp disable originate > -------mpd.links--------- > > ----------------------- > Omer Faruk Sen > http://www.EnderUNIX.ORG > Software Development Team @ Turkey > http://www.Faruk.NET > For Public key: http://www.enderunix.org/ofsen/ofsen.asc > ******************************************************** >