From owner-freebsd-questions@FreeBSD.ORG Sun May 15 18:04:22 2011 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id BCADD1065670 for ; Sun, 15 May 2011 18:04:22 +0000 (UTC) (envelope-from lobo@bsd.com.br) Received: from mail-yi0-f54.google.com (mail-yi0-f54.google.com [209.85.218.54]) by mx1.freebsd.org (Postfix) with ESMTP id 71B718FC08 for ; Sun, 15 May 2011 18:04:22 +0000 (UTC) Received: by yie12 with SMTP id 12so1523275yie.13 for ; Sun, 15 May 2011 11:04:21 -0700 (PDT) Received: by 10.236.186.106 with SMTP id v70mr3445403yhm.207.1305482660864; Sun, 15 May 2011 11:04:20 -0700 (PDT) Received: from papi.localnet ([187.112.4.223]) by mx.google.com with ESMTPS id x76sm2031941yhn.94.2011.05.15.11.04.18 (version=TLSv1/SSLv3 cipher=OTHER); Sun, 15 May 2011 11:04:19 -0700 (PDT) To: freebsd-questions@freebsd.org From: Mario Lobo Date: Sun, 15 May 2011 15:03:19 -0300 X-KMail-Markup: true MIME-Version: 1.0 Message-Id: <201105151503.19272.lobo@bsd.com.br> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Subject: pptpd problem (re-post) X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 May 2011 18:04:22 -0000 Sorry for the re-post but I am really lost here. Any hints, clues, pointers, opinions would be appreciated. I have a VPN server on FBSD 8.1. The vpn closes fine. But as soon as I start doing something with an inside LAN machine i.e. an RDP session, I get this: May 14 12:46:06 suporte pptpd[1958]: GRE: xmit failed from decaps_hdlc: No buffer space available and the VPN tunnel drops. I googled a lot for it but I didn't find any thing that could help. The system WAS working OK before. I tried everything I could think of. Could anyone help? Thanks, -- Mario Lobo http://www.mallavoodoo.com.br FreeBSD since 2.2.8 [not Pro-Audio.... YET!!] (99% winblows FREE) pptpd: poptop-1.3.4_2 System: FreeBSD 8.1-STABLE #0: Mon Feb 28 20:47:00 BRT 2011 i386 last pid: 2145; load averages: 0.00, 0.00, 0.00 28 processes: 1 running, 27 sleeping CPU: 0.0% user, 0.0% nice, 0.0% system, 1.1% interrupt, 98.9% idle Mem: 15M Active, 13M Inact, 58M Wired, 28K Cache, 44M Buf, 1892M Free Swap: 4000M Total, 4000M Free sysctl.conf: security.bsd.see_other_uids=0 security.bsd.see_other_gids=0 debug.cpufreq.lowest=400 kern.maxfiles=65536 kern.maxfilesperproc=32768 kern.maxvnodes=600000 kern.ipc.shmmax=67108864 kern.ipc.shmall=16384 kern.ipc.nmbclusters=32768 kern.ipc.somaxconn=32768 net.inet.tcp.rfc1323=1 net.inet.tcp.drop_synfin=1 net.inet.tcp.sendspace=65536 net.inet.tcp.recvspace=65536 net.inet.tcp.blackhole=2 net.inet.udp.blackhole=1 net.inet.icmp.drop_redirect=1 net.inet.icmp.icmplim_output=0 net.inet.icmp.icmplim=2000 net.inet.tcp.path_mtu_discovery=0 net.inet.tcp.recvbuf_auto=1 net.inet.tcp.recvbuf_inc=16384 net.inet.tcp.recvbuf_max=16777216 net.inet.tcp.sendbuf_auto=1 net.inet.tcp.sendbuf_inc=8192 net.inet.tcp.sendbuf_max=16777216 pf.conf(relevant rules): #--- Allow vpns from anywhere to anywhere pass log quick on $ext_if inet proto gre all queue (ssh_bulk, ack) pass log quick on $ext_if inet proto tcp from any to any port pptp flags S/SA queue (ssh_bulk, ack) pass log quick on $aln_if inet proto gre all queue (ssh_bulk, ack) pass log quick on $aln_if inet proto tcp from any to any port pptp flags S/SA queue (ssh_bulk, ack) options.pptpd: proxyarp lock name ppp.conf: default: set timeout 1200 # set log Phase Chat LCP IPCP CCP TUN Command Connect set log Phase Chat TUN Connect set dial set login set ifaddr 172.16.3.200/24 172.16.3.201-172.16.3.239 255.255.255.0 set server /tmp/tun%d "" 0177 # set lqrperiod 20 # set echoperiod 20 # enable lqr echo pptp: disable ipv6cp pap chap disable deflate pred1 deny deflate pred1 enable proxy accept dns set mtu max 1024 set dns 172.16.3.133 set nbns 172.16.3.133 enable MSChapV2 enable mppe set mppe * stateful set radius /etc/ppp/radius.conf set rad_alive 60 allow mode direct