radius | pptpd | No port type found. Rejecting
Проверьте:kop писал(а):Все вроде нормально влогах кроме ppp.log
Phase: radius(auth): No valid RADIUS responses recaived
Phase: Chap Output: FAILURE
????
И клиент впн говарит ошибка 691=(
1) Секретные слова на клиенте и на радиус-сервере.
2) Проверьте по tcpdump приходят ли ответы на/от радиус-сервера и с каких адресов ?
Секретные слова нормально
по tcpdump
12:21:50.624819 IP 172.33.0.2 > xxxxxxxxxxxx: call 1024 seq 2 gre-ppp-payload
12:21:50.625295 IP xxxxxxxxxxx > 172.33.0.2: call 0 seq 1 ack 2 gre-ppp-payloa d
12:21:50.626005 IP 172.33.0.2 > xxxxxxxxx: call 1024 seq 3 ack 1 gre-ppp-pay load
12:21:50.626661 IP xxxxxxxx > 172.33.0.2: call 0 seq 2 ack 3 gre-ppp-payloa d
12:21:50.626674 IP xxxxxxxx > 172.33.0.2: call 0 seq 3 gre-ppp-payload
12:21:50.627404 IP 172.33.0.2.1111 > xxxxxxxx.pptp: P 349:373(24) ack 189 w in 65347: pptp CTRL_MSGTYPE=SLI PEER_CALL_ID(1024) SEND_ACCM(0x00000000) RECV_AC CM(0xffffffff)
12:21:50.627844 IP 172.33.0.2 > xxxxxxxx: call 1024 seq 4 ack 3 gre-ppp-pay load
12:21:50.628228 IP 172.33.0.2 > xxxxxx: call 1024 seq 5 gre-ppp-payload
12:21:50.628747 IP 172.33.0.2 > xxxxxxxxx: call 1024 seq 6 gre-ppp-payload
12:21:50.633952 IP xxxxxxxxxxx > 172.33.0.2: call 0 seq 4 ack 6 gre-ppp-payloa d
12:21:50.633965 IP xxxxxxxx > 172.33.0.2: call 0 seq 5 gre-ppp-payload
12:21:50.645217 IP 172.33.0.2 > xxxxxxxxxx: call 1024 seq 7 ack 5 gre-ppp-pay load
12:21:50.645714 IP xxxxxxxxxx.pptp > 172.33.0.2.1111: F 189:189(0) ack 373 wi n 65535
12:21:50.645967 IP 172.33.0.2.1111 > xxxxxxxxxxx.pptp: FP 373:397(24) ack 190 win 65347: pptp CTRL_MSGTYPE=SLI PEER_CALL_ID(1024) SEND_ACCM(0xffffffff) RECV_A CCM(0xffffffff)
12:21:50.646035 IP xxxxxxxxxxx.pptp > 172.33.0.2.1111: R 3100085347:3100085347 (0) win 0
по tcpdump
12:21:50.624819 IP 172.33.0.2 > xxxxxxxxxxxx: call 1024 seq 2 gre-ppp-payload
12:21:50.625295 IP xxxxxxxxxxx > 172.33.0.2: call 0 seq 1 ack 2 gre-ppp-payloa d
12:21:50.626005 IP 172.33.0.2 > xxxxxxxxx: call 1024 seq 3 ack 1 gre-ppp-pay load
12:21:50.626661 IP xxxxxxxx > 172.33.0.2: call 0 seq 2 ack 3 gre-ppp-payloa d
12:21:50.626674 IP xxxxxxxx > 172.33.0.2: call 0 seq 3 gre-ppp-payload
12:21:50.627404 IP 172.33.0.2.1111 > xxxxxxxx.pptp: P 349:373(24) ack 189 w in 65347: pptp CTRL_MSGTYPE=SLI PEER_CALL_ID(1024) SEND_ACCM(0x00000000) RECV_AC CM(0xffffffff)
12:21:50.627844 IP 172.33.0.2 > xxxxxxxx: call 1024 seq 4 ack 3 gre-ppp-pay load
12:21:50.628228 IP 172.33.0.2 > xxxxxx: call 1024 seq 5 gre-ppp-payload
12:21:50.628747 IP 172.33.0.2 > xxxxxxxxx: call 1024 seq 6 gre-ppp-payload
12:21:50.633952 IP xxxxxxxxxxx > 172.33.0.2: call 0 seq 4 ack 6 gre-ppp-payloa d
12:21:50.633965 IP xxxxxxxx > 172.33.0.2: call 0 seq 5 gre-ppp-payload
12:21:50.645217 IP 172.33.0.2 > xxxxxxxxxx: call 1024 seq 7 ack 5 gre-ppp-pay load
12:21:50.645714 IP xxxxxxxxxx.pptp > 172.33.0.2.1111: F 189:189(0) ack 373 wi n 65535
12:21:50.645967 IP 172.33.0.2.1111 > xxxxxxxxxxx.pptp: FP 373:397(24) ack 190 win 65347: pptp CTRL_MSGTYPE=SLI PEER_CALL_ID(1024) SEND_ACCM(0xffffffff) RECV_A CCM(0xffffffff)
12:21:50.646035 IP xxxxxxxxxxx.pptp > 172.33.0.2.1111: R 3100085347:3100085347 (0) win 0
Help PLIZZZ???
????
?Debug : Feb 05 18:10:27 RFW URFA[plugin]: Got 'exec' command...
?Debug : Feb 05 18:10:27 FWCntl: Executing FW rule: /sbin/ipfw add 5001 allow ip from 172.21.0.2/24 to any
?Debug : Feb 05 18:10:27 RFW URFA[plugin]: Got 'exec' command...
?Debug : Feb 05 18:10:27 FWCntl: Executing FW rule: /sbin/ipfw add 5001 allow ip from any to 172.21.0.2/24
ipfw: bad command `/sbin/ipfw'
ipfw: bad command `/sbin/ipfw'
?Debug : Feb 05 18:10:27 RFW URFA[plugin]: Got 'exec' command...
?Debug : Feb 05 18:10:27 FWCntl: Executing FW rule: /sbin/ipfw add 5001 allow ip from 172.21.0.2/24 to any
?Debug : Feb 05 18:10:27 RFW URFA[plugin]: Got 'exec' command...
?Debug : Feb 05 18:10:27 FWCntl: Executing FW rule: /sbin/ipfw add 5001 allow ip from any to 172.21.0.2/24
ipfw: bad command `/sbin/ipfw'
ipfw: bad command `/sbin/ipfw'
- kaN5300
- Сообщения: 480
- Зарегистрирован: Пт янв 21, 2005 17:27
- Откуда: Ыукзгрщм
- Контактная информация:
Re: Help PLIZZZ???
гыыы, я тольно недавно с этим сношался - в конве пишите /sbin/ipfw а в и-фейсе админа просто add... чтобы буть не дублировалсяkop писал(а):????
?Debug : Feb 05 18:10:27 RFW URFA[plugin]: Got 'exec' command...
?Debug : Feb 05 18:10:27 FWCntl: Executing FW rule: /sbin/ipfw add 5001 allow ip from 172.21.0.2/24 to any
?Debug : Feb 05 18:10:27 RFW URFA[plugin]: Got 'exec' command...
?Debug : Feb 05 18:10:27 FWCntl: Executing FW rule: /sbin/ipfw add 5001 allow ip from any to 172.21.0.2/24
ipfw: bad command `/sbin/ipfw'
ipfw: bad command `/sbin/ipfw'
- kaN5300
- Сообщения: 480
- Зарегистрирован: Пт янв 21, 2005 17:27
- Откуда: Ыукзгрщм
- Контактная информация:
Всё решилось правкой конфига для радиуса:
Код: Выделить всё
core_host=127.0.0.1
core_port=11758
radius_acct_port=1813
radius_auth_port=1812
radius_auth_mppe=disable
radius_login=radius
radius_password=radius
log_file_main=/netup/utm5/log/radius_main.log
log_file_debug=/netup/utm5/log/radius_main.log
radius_max_session_age=0