Страница 1 из 2

VPN??

Добавлено: 19 ноя 2005, 19:50
Jeefo
Подключаюсь на VPN (хотя я точно не уверен)

Код: Выделить всё

Using interface ppp0
Connect: ppp0 <--> /dev/pts/2
PAP authentication succeeded
not replacing default route to eth0 [192.168]
Cannot determine ethernet address for proxy ARP
local  IP address 
remote IP address 
CCP terminated by peer
Compression disabled by peer.
Terminating on signal 2
Connect time 0.2 minutes.
Sent 27 bytes, received 27 bytes.
Terminating on signal 15
Connection terminated.
Modem hangup
и не могу открывать сайты

Код: Выделить всё

PING www.yahoo.akadns.net (68.142.226.48) 56(84) bytes of data.
From 10.5.5.1 icmp_seq=5 Packet filtered
From 10.5.5.1 icmp_seq=8 Packet filtered

--- www.yahoo.akadns.net ping statistics ---
9 packets transmitted, 0 received, +2 errors, 100% packet loss, time 8072ms
В чем может быть проблема??

plz help

Добавлено: 19 ноя 2005, 22:03
Llama
Jeefo, добавь в опции pptpd опцию debug и покажи еще раз логи... По каким-то причинам, соединения обрвается после того, как ты не полчил ip-адреса. ИМХО причина в том, что используется PAP-аутентификация. Укажи плс. провайдера, если это Беларуский провайде - есть шанс что тебе подскажу что-то более детельно по настройкам.

Добавлено: 19 ноя 2005, 23:26
Jeefo
Провайдер Гомельский "Сервер"

Код: Выделить всё

using channel 1
Using interface ppp0
Connect: ppp0 <--> /dev/pts/2
sent [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0x5e14cfcc> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <mru 1492> <auth pap> <magic 0x6b093b1a>]
sent [LCP ConfAck id=0x1 <mru 1492> <auth pap> <magic 0x6b093b1a>]
rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0x5e14cfcc> <pcomp> <accomp>]
sent [LCP EchoReq id=0x0 magic=0x5e14cfcc]
sent [PAP AuthReq id=0x1 user="jeefo" password=<hidden>]
rcvd [LCP EchoRep id=0x0 magic=0x6b093b1a]
rcvd [PAP AuthAck id=0x1 ""]
PAP authentication succeeded
sent [CCP ConfReq id=0x1 <deflate 15> <deflate(old#) 15> <bsd v1 15>]
sent [IPCP ConfReq id=0x1 <compress VJ 0f 01> <addr 0.0.0.0>]
rcvd [IPCP ConfReq id=0x1 <compress VJ 0f 00> <addr 217.21.59.254>]
sent [IPCP ConfAck id=0x1 <compress VJ 0f 00> <addr 217.21.59.254>]
rcvd [CCP ConfReq id=0x1 <mppe -H -M -S -L -D +C>]
sent [CCP ConfRej id=0x1 <mppe -H -M -S -L -D +C>]
rcvd [CCP ConfRej id=0x1 <deflate 15> <deflate(old#) 15> <bsd v1 15>]
sent [CCP ConfReq id=0x2]
rcvd [IPCP ConfNak id=0x1 <addr 213.184.245.143>]
sent [IPCP ConfReq id=0x2 <compress VJ 0f 01> <addr 213.184.245.143>]
rcvd [CCP ConfReq id=0x2 < 17 06 00 01 02 00>]
sent [CCP ConfRej id=0x2 < 17 06 00 01 02 00>]
rcvd [CCP ConfAck id=0x2]
rcvd [IPCP ConfAck id=0x2 <compress VJ 0f 01> <addr 213.184.245.143>]
not replacing default route to eth0 [192.168.21.100]
Cannot determine ethernet address for proxy ARP
local  IP address 213.184.245.143
remote IP address 217.21.59.254
Script /etc/ppp/ip-up started (pid 5989)
rcvd [CCP ConfReq id=0x3 < 11 05 00 01 01>]
sent [CCP ConfRej id=0x3 < 11 05 00 01 01>]
Script ?? finished (pid 5958), status = 0x0
Script /etc/ppp/ip-up finished (pid 5989), status = 0x0
rcvd [CCP ConfReq id=0x4 < 11 05 00 01 03>]
sent [CCP ConfRej id=0x4 < 11 05 00 01 03>]
rcvd [CCP ConfReq id=0x5 <predictor 1>]
sent [CCP ConfRej id=0x5 <predictor 1>]
rcvd [CCP ConfReq id=0x6]
sent [CCP ConfAck id=0x6]
rcvd [CCP TermReq id=0x7]
CCP terminated by peer
sent [CCP TermAck id=0x7]
Compression disabled by peer.
rcvd [CCP ConfReq id=0x8 <mppe -H -M -S -L -D +C>]
sent [CCP ConfReq id=0x3 <deflate 15> <deflate(old#) 15> <bsd v1 15>]
sent [CCP ConfRej id=0x8 <mppe -H -M -S -L -D +C>]
rcvd [CCP ConfRej id=0x3 <deflate 15> <deflate(old#) 15> <bsd v1 15>]
sent [CCP ConfReq id=0x4]
rcvd [CCP ConfReq id=0x9 < 17 06 00 01 02 00>]
sent [CCP ConfRej id=0x9 < 17 06 00 01 02 00>]
rcvd [CCP ConfAck id=0x4]
rcvd [CCP ConfReq id=0xa < 11 05 00 01 01>]
sent [CCP ConfRej id=0xa < 11 05 00 01 01>]
rcvd [CCP ConfReq id=0xb < 11 05 00 01 03>]
sent [CCP ConfRej id=0xb < 11 05 00 01 03>]
rcvd [CCP ConfReq id=0xc <predictor 1>]
sent [CCP ConfRej id=0xc <predictor 1>]
rcvd [CCP ConfReq id=0xd]
sent [CCP ConfAck id=0xd]
rcvd [CCP TermReq id=0xe]
CCP terminated by peer
sent [CCP TermAck id=0xe]
Compression disabled by peer.
Terminating on signal 2
Connect time 1.8 minutes.
Sent 316 bytes, received 316 bytes.
Script /etc/ppp/ip-down started (pid 6069)
sent [LCP TermReq id=0x2 "User request"]
Terminating on signal 15
Script /etc/ppp/ip-down finished (pid 6069), status = 0x0
rcvd [CCP ConfReq id=0x24 <mppe -H -M -S -L -D +C>]
Discarded non-LCP packet when LCP not open
Terminating on signal 2
Terminating on signal 15
sent [LCP TermReq id=0x3 "User request"]
Connection terminated.
Modem hangup

Добавлено: 19 ноя 2005, 23:51
Llama
Судя по всему, провайдер не поддерживает компрессию которую "хочет" pptp.
Покажи опции pptp.
Потом добавь опцию require-mppe и покажи что получилось. Если все равно не работает - добавь еще nobsdcomp и nodeflate и покажи снова лог.

Добавлено: 20 ноя 2005, 00:42
Jeefo
Попробовал require-mppe.Выдало:

Код: Выделить всё

using channel 2
Using interface ppp0
Connect: ppp0 <--> /dev/pts/2
sent [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0xc6ac20a7> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <mru 1492> <auth pap> <magic 0x6b3aefde>]
sent [LCP ConfAck id=0x1 <mru 1492> <auth pap> <magic 0x6b3aefde>]
rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0xc6ac20a7> <pcomp> <accomp>]
sent [LCP EchoReq id=0x0 magic=0xc6ac20a7]
sent [PAP AuthReq id=0x1 user="jeefo" password=<hidden>]
rcvd [LCP EchoRep id=0x0 magic=0x6b3aefde]
rcvd [PAP AuthAck id=0x1 ""]
PAP authentication succeeded
MPPE required, but MS-CHAP[v2] auth not performed.
sent [LCP TermReq id=0x2 "MPPE required but not available"]
rcvd [IPCP ConfReq id=0x1 <compress VJ 0f 00> <addr 217.21.59.254>]
Discarded non-LCP packet when LCP not open
rcvd [CCP ConfReq id=0x1 <mppe -H -M -S -L -D +C>]
Discarded non-LCP packet when LCP not open
rcvd [LCP TermAck id=0x2]
Connection terminated.
Добавил еще nobsdcomp и nodeflate:

Код: Выделить всё

using channel 3
Using interface ppp0
Connect: ppp0 <--> /dev/pts/2
sent [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0x65147c3a> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <mru 1492> <auth pap> <magic 0x6b3c5a65>]
sent [LCP ConfAck id=0x1 <mru 1492> <auth pap> <magic 0x6b3c5a65>]
rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0x65147c3a> <pcomp> <accomp>]
sent [LCP EchoReq id=0x0 magic=0x65147c3a]
sent [PAP AuthReq id=0x1 user="jeefo" password=<hidden>]
rcvd [LCP EchoRep id=0x0 magic=0x6b3c5a65]
rcvd [PAP AuthAck id=0x1 ""]
PAP authentication succeeded
MPPE required, but MS-CHAP[v2] auth not performed.
sent [LCP TermReq id=0x2 "MPPE required but not available"]
rcvd [LCP TermAck id=0x2]
Connection terminated.
+Опции

Код: Выделить всё

###############################################################################
# $Id: pptpd-options 4255 2004-10-03 18:44:00Z rene $
#
# Sample Poptop PPP options file /etc/ppp/pptpd-options
# Options used by PPP when a connection arrives from a client.
# This file is pointed to by /etc/pptpd.conf option keyword.
# Changes are effective on the next connection.  See "man pppd".
#
# You are expected to change this file to suit your system.  As
# packaged, it requires PPP 2.4.2 and the kernel MPPE module.
###############################################################################


# Authentication

# Name of the local system for authentication purposes 
# (must match the second field in /etc/ppp/chap-secrets entries)
name pptpd

# Optional: domain name to use for authentication
# domain mydomain.net

# Strip the domain prefix from the username before authentication.
# (applies if you use pppd with chapms-strip-domain patch)
#chapms-strip-domain


# Encryption
# Debian: on systems with a kernel built with the package
# kernel-patch-mppe >= 2.4.2 and using ppp >= 2.4.2, ...
# {{{
refuse-pap
#refuse-chap
#refuse-mschap
# Require the peer to authenticate itself using MS-CHAPv2 [Microsoft
# Challenge Handshake Authentication Protocol, Version 2] authentication.
require-mschap-v2
# Require MPPE 128-bit encryption
# (note that MPPE requires the use of MSCHAP-V2 during authentication)
#require-mppe-128
# }}}




# Network and Routing

# If pppd is acting as a server for Microsoft Windows clients, this
# option allows pppd to supply one or two DNS (Domain Name Server)
# addresses to the clients.  The first instance of this option
# specifies the primary DNS address; the second instance (if given)
# specifies the secondary DNS address.
#ms-dns 10.0.0.1
#ms-dns 10.0.0.2

# If pppd is acting as a server for Microsoft Windows or "Samba"
# clients, this option allows pppd to supply one or two WINS (Windows
# Internet Name Services) server addresses to the clients.  The first
# instance of this option specifies the primary WINS address; the
# second instance (if given) specifies the secondary WINS address.
#ms-wins 10.0.0.3
#ms-wins 10.0.0.4

# Add an entry to this system's ARP [Address Resolution Protocol]
# table with the IP address of the peer and the Ethernet address of this
# system.  This will have the effect of making the peer appear to other
# systems to be on the local ethernet.
# (you do not need this if your PPTP server is responsible for routing
# packets to the clients -- James Cameron)
proxyarp

# Debian: do not replace the default route
nodefaultroute


# Logging

# Enable connection debugging facilities.
# (see your syslog configuration for where pppd sends to)
debug

# Print out all the option values which have been set.
# (often requested by mailing list to verify options)
#dump


# Miscellaneous

# Create a UUCP-style lock file for the pseudo-tty to ensure exclusive
# access.
lock

# Disable BSD-Compress compression
nobsdcomp 

Добавлено: 20 ноя 2005, 12:25
Llama
Гм, а что за дистрибутив, что за ядро?
Есть мнение, что поддержки mppe...

Добавлено: 20 ноя 2005, 15:41
Jeefo
Linux debian 2.6.8-2-k7 #1 Thu May 19 18:03:29 JST 2005 i686 GNU/Linux

Добавлено: 20 ноя 2005, 15:53
Llama
это ядро не умеет MPPE/MPPC - надо установить из дистрибутива исходники ядра (kernel-source-2.6.8), kernel-patch-mppe и kernel-package. далее, man make-kpkg.
http://citforum.ru/open_source/deb_notes/kernel/
http://pptpclient.sourceforge.net/howto ... uild.phtml
буде что-то типа
make-kpgk bianry-arch --initrd --added-patches mppe
После чего установить полученый пакет с ядром.

Добавлено: 26 ноя 2005, 15:50
Jeefo
Вроде добавил подержку mppe к ядру и все равно не хочет конектится.


С require-mppe.Выдало:

Код: Выделить всё

using channel 5
Using interface ppp0
Connect: ppp0 <--> /dev/pts/2
sent [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0x37c7cb7f> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <mru 1492> <auth pap> <magic 0x8a8033ae>]
sent [LCP ConfAck id=0x1 <mru 1492> <auth pap> <magic 0x8a8033ae>]
rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0x37c7cb7f> <pcomp> <accomp>]
sent [LCP EchoReq id=0x0 magic=0x37c7cb7f]
sent [PAP AuthReq id=0x1 user="jeefo" password=<hidden>]
rcvd [LCP EchoRep id=0x0 magic=0x8a8033ae]
rcvd [PAP AuthAck id=0x1 ""]
PAP authentication succeeded
MPPE required, but MS-CHAP[v2] auth not performed.
sent [LCP TermReq id=0x2 "MPPE required but not available"]
rcvd [LCP TermAck id=0x2]
Connection terminated.
А с nobsdcomp и nodeflate:

Код: Выделить всё

using channel 5
Using interface ppp0
Connect: ppp0 <--> /dev/pts/3
sent [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0xdc7c0493> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <mru 1492> <auth pap> <magic 0x8d6cf4c7>]
sent [LCP ConfAck id=0x1 <mru 1492> <auth pap> <magic 0x8d6cf4c7>]
rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0xdc7c0493> <pcomp> <accomp>]
sent [LCP EchoReq id=0x0 magic=0xdc7c0493]
sent [PAP AuthReq id=0x1 user="jeefo" password=<hidden>]
rcvd [LCP EchoRep id=0x0 magic=0x8d6cf4c7]
rcvd [PAP AuthNak id=0x1 "\r\nAccess denied (external check failed)."]
Remote message: ^M^JAccess denied (external check failed).
PAP authentication failed
sent [LCP TermReq id=0x2 "Failed to authenticate ourselves to peer"]
Terminating on signal 15
sent [LCP TermReq id=0x3 "User request"]
Connection terminated.
Modem hangup

Добавлено: 28 ноя 2005, 17:58
Denis
ключевые фразы:
PAP authentication succeeded
MPPE required, but MS-CHAP[v2] auth not performed.

а также:
(note that MPPE requires the use of MSCHAP-V2 during authentication)

перевести?

Добавлено: 28 ноя 2005, 20:20
Llama
Jeefo, Покажи также вывод lsmod. Покажи также chap-secrets заменив пароль звездочками ;)
поподбуй добавить опции по одной...:

Код: Выделить всё

require-mppe-40
require-mppe-128
require-mppe

Добавлено: 29 ноя 2005, 15:31
Jeefo
Если оно требует MSCHAP-V2, то как сделать что бы использавала PAP??

В настройках винды шифрование данных: необязательное(подкл. даже без шифрования) и разрешен только один протокол PAP.

Добавлено: 29 ноя 2005, 15:54
Llama
Jeefo, ах вот оно как...
ну тогда менем в опциях с точностью до наоборот:
refuse-mschap-v2
require-pap

Добавлено: 29 ноя 2005, 17:58
Jeefo
По менял в файле эти значения и выдало :

Код: Выделить всё

/usr/sbin/pppd: The remote system is required to authenticate itself
/usr/sbin/pppd: but I couldn't find any suitable secret (password) for it to use to do so.
:oops:У меня такое чувство будто я что то делаю не так или не там меняю значения.:oops:

Добавлено: 29 ноя 2005, 18:10
Denis
покажи chap и pap -secrets
нужно в pap-secrers:

login pptpd password