[pfSense Support] PPTP VPN not working consistently

2007-09-05 Thread Sonny Sarai

Hello,

I added a post a few weeks back regarding why PPTP VPN connects at times 
and other times it just hangs but I received no response.
This is why I am adding another post. I have pfsense 1.2 RC2. and I have 
set up PPTP VPN. I can connect about 70% of the time and the other 
timers I cannot. neither can our staff. I have entered a rule in our 
firewall to let PPTP clients open access as well as GRE but still nothing.


Nothing is added or has been removed from the firewall but still 
nothing. As our company is growing, VPN is becoming more critical. I 
have been doing some research in the forums but I did not get anything 
concrete as to why this happens.


Our sister company in Stockholm is running pfsense 1.2 RC2 and I can 
connect to them. I have mirrored their settings but I still cannot 
consistently connect. I am looking for pattern such as a specific time 
in the day or the number of times I connect. Is there a limit to how 
many times a client can VPN in before they are blocked for some time?


Any suggestions would be greatly appreciated. I need to be able to 
connect to VPN consistently


Thank you,

Sonny


-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] PPTP VPN not working consistently

2007-09-05 Thread Jaye Mathisen
I have had to remove the scrub options for some reason.

Customers on ATT's network, it looks like around the country, but not
verified, as I don't have customers anywhere, can't pass anything but
the smallest datasets to me if the router has the scrub options.

If I take that out, the same customers work great.

On Wed, Sep 05, 2007 at 08:23:52PM -0700, Sonny Sarai wrote:
 Hello,
 
 I added a post a few weeks back regarding why PPTP VPN connects at times 
 and other times it just hangs but I received no response.
 This is why I am adding another post. I have pfsense 1.2 RC2. and I have 
 set up PPTP VPN. I can connect about 70% of the time and the other 
 timers I cannot. neither can our staff. I have entered a rule in our 
 firewall to let PPTP clients open access as well as GRE but still nothing.
 
 Nothing is added or has been removed from the firewall but still 
 nothing. As our company is growing, VPN is becoming more critical. I 
 have been doing some research in the forums but I did not get anything 
 concrete as to why this happens.
 
 Our sister company in Stockholm is running pfsense 1.2 RC2 and I can 
 connect to them. I have mirrored their settings but I still cannot 
 consistently connect. I am looking for pattern such as a specific time 
 in the day or the number of times I connect. Is there a limit to how 
 many times a client can VPN in before they are blocked for some time?
 
 Any suggestions would be greatly appreciated. I need to be able to 
 connect to VPN consistently
 
 Thank you,
 
 Sonny
 
 
 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]
 
 
 !DSPAM:46df73e0369906216912515!
 

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] PPTP VPN not working consistently

2007-09-05 Thread Scott Ullrich
On 9/5/07, Jaye Mathisen [EMAIL PROTECTED] wrote:
 I have had to remove the scrub options for some reason.

 Customers on ATT's network, it looks like around the country, but not
 verified, as I don't have customers anywhere, can't pass anything but
 the smallest datasets to me if the router has the scrub options.

 If I take that out, the same customers work great.

Have you tried to disable scrubbing in System - Advanced?

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] PPTP VPN not working consistently

2007-09-05 Thread Jaye Mathisen
On Wed, Sep 05, 2007 at 11:34:26PM -0400, Scott Ullrich wrote:
 On 9/5/07, Jaye Mathisen [EMAIL PROTECTED] wrote:
  I have had to remove the scrub options for some reason.
 
  Customers on ATT's network, it looks like around the country, but not
  verified, as I don't have customers anywhere, can't pass anything but
  the smallest datasets to me if the router has the scrub options.
 
  If I take that out, the same customers work great.
 
 Have you tried to disable scrubbing in System - Advanced?
 

Yeah, that's what I meant by remove, I just couldn't remember the location
in all the menus.

It appears to be a moderately recent development, as these same customers
have been able to use it before, but I can't tie it specifically to
a pfsense upgrade, only that starting about the 25th of August, that's
what I had to do to get things to work.

Hadn't touched the rulesets in ages, just updated to the latest RC...

WHat's odd is that tcpdump would show the incoming packet, but the
application never saw the connection get completed and handed off, and
the kernel never responded.

Disable scrub, voila'...

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] PPTP VPN not working consistently

2007-09-05 Thread Sonny Sarai
Thank you both for replying so quickly. I have disabled scrubbing. 
Should I wait a while before I can tell if it worked or not? It is not 
working right now. Do I need to reboot if it does not work.


Thanks again,

Sonny

Scott Ullrich wrote:

On 9/5/07, Jaye Mathisen [EMAIL PROTECTED] wrote:
  

I have had to remove the scrub options for some reason.

Customers on ATT's network, it looks like around the country, but not
verified, as I don't have customers anywhere, can't pass anything but
the smallest datasets to me if the router has the scrub options.

If I take that out, the same customers work great.



Have you tried to disable scrubbing in System - Advanced?

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

  





-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] PPTP VPN not working consistently

2007-09-05 Thread Jaye Mathisen
I don't know if the reload filter actually reloads everything,
or just the rules or queues... I don't see how it can hurt to
reboot and check.

If turning off scrub doesn't help, you definitely want to turn
it back on...

On Wed, Sep 05, 2007 at 08:57:41PM -0700, Sonny Sarai wrote:
 Thank you both for replying so quickly. I have disabled scrubbing. 
 Should I wait a while before I can tell if it worked or not? It is not 
 working right now. Do I need to reboot if it does not work.
 
 Thanks again,
 
 Sonny
 
 Scott Ullrich wrote:
 On 9/5/07, Jaye Mathisen [EMAIL PROTECTED] wrote:
   
 I have had to remove the scrub options for some reason.
 
 Customers on ATT's network, it looks like around the country, but not
 verified, as I don't have customers anywhere, can't pass anything but
 the smallest datasets to me if the router has the scrub options.
 
 If I take that out, the same customers work great.
 
 
 Have you tried to disable scrubbing in System - Advanced?
 
 Scott
 
 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]
 
   
 
 
 
 
 -
 To unsubscribe, e-mail: [EMAIL PROTECTED]
 For additional commands, e-mail: [EMAIL PROTECTED]
 
 
 !DSPAM:46df7bc2373906284142498!
 

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]



Re: [pfSense Support] PPTP VPN not working consistently

2007-09-05 Thread Sonny Sarai

Hi Jaye,

Thanks for your tips. The scrub did not change anything. I still cannot 
connect. I checked off Clear DF bit instead of dropping to see if that 
changed anything but I still cannot connect.


I took your advice and turned scrub back on after about a half an hour 
of not connecting. Do you think it is a good idea if I ssh in and dig 
deeper via command line to see what is holding up the connection?


I am stumped on this one. The only difference between our pfsense and 
our sister company in Stockholm is our lan interface is bridged to

our wan interface. But I do not see how that would make a difference.

Any other suggestions is appreciated,

Thank you,

Sonny



Jaye Mathisen wrote:

I don't know if the reload filter actually reloads everything,
or just the rules or queues... I don't see how it can hurt to
reboot and check.

If turning off scrub doesn't help, you definitely want to turn
it back on...

On Wed, Sep 05, 2007 at 08:57:41PM -0700, Sonny Sarai wrote:
  
Thank you both for replying so quickly. I have disabled scrubbing. 
Should I wait a while before I can tell if it worked or not? It is not 
working right now. Do I need to reboot if it does not work.


Thanks again,

Sonny

Scott Ullrich wrote:


On 9/5/07, Jaye Mathisen [EMAIL PROTECTED] wrote:
 
  

I have had to remove the scrub options for some reason.

Customers on ATT's network, it looks like around the country, but not
verified, as I don't have customers anywhere, can't pass anything but
the smallest datasets to me if the router has the scrub options.

If I take that out, the same customers work great.
   


Have you tried to disable scrubbing in System - Advanced?

Scott

-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

 
  



-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]


!DSPAM:46df7bc2373906284142498!




-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

  





-
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]