mpd5 l2tp авторизация проблема

Технические вопросы по UTM 5.0
Закрыто
kirush
Сообщения: 699
Зарегистрирован: Пт фев 04, 2005 13:58

mpd5 l2tp авторизация проблема

Сообщение kirush »

Доброе время суток!
Подскажите пожалуйста, что не так настроил:

pptp работает, а l2tp периодически разрывает соединение (тестировал с роутера, если цепляться компом то ситуация гораздо лучше). Может кто то поделится конфигом l2tp для роутеров?

Мой конфиг:

Код: Выделить всё

l2tp_server:

    create bundle template C
    set iface enable proxy-arp
    set iface disable on-demand
    set iface idle -1
    set iface enable tcpmssfix
    set ipcp yes vjcomp
    set ipcp dns 10.1.255.253
    set ipcp ranges 172.16.200.2/32 0.0.0.0/0

    set bundle enable compression
    set bundle no crypt-reqd
    set ccp yes mppc
    set mppc yes e40
    set mppc yes e128
    set mppc yes stateless

    create link template N l2tp
    set link action bundle C
    set link disable multilink
    set link yes acfcomp protocomp
    set link no pap chap
    set link enable chap
    set link yes chap-msv2
    set link max-redial -1
    set link mtu 1460
    set link enable peer-as-calling
    set link disable keep-ms-domain
    set l2tp self 10.1.255.251
    set link enable incoming
    set auth enable radius-auth
    load radius

radius:
    set radius server 127.0.0.1 netup 1812 1813
    set radius timeout 10
    set radius retries 3
    set radius config /usr/local/etc/radius.conf
    set auth enable radius-auth
    set auth enable radius-acct
    set radius enable message-authentic
    set auth acct-update 300
    set radius me 10.1.255.251

Код: Выделить всё

Mar 29 00:33:13 vpn2 mpd: Incoming L2TP packet from 10.1.0.6 1701
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; L2TP&#58; Control connection 0x28805e08 10.1.255.251 1701 <-> 10.1.0.6 1701 connected
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; L2TP&#58; Incoming call #0 via connection 0x28805e08 received
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; L2TP&#58; Incoming call #0 via control connection 0x28805e08 accepted
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; OPEN event
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; Open event
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Initial --> Starting
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; LayerStart
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; L2TP&#58; Call #0 connected
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; UP event
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; Up event
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Starting --> Req-Sent
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; SendConfigReq #1
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93;   ACFCOMP
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93;   PROTOCOMP
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93;   MRU 1500
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93;   MAGICNUM 1a93e62e
Mar 29 00&#58;33&#58;13 vpn2 mpd&#58; &#91;N-2&#93;   AUTHPROTO CHAP MSOFTv2
Mar 29 00&#58;33&#58;14 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; rec'd Configure Request #1 &#40;Req-Sent&#41;
Mar 29 00&#58;33&#58;14 vpn2 mpd&#58; &#91;N-2&#93;   MAGICNUM 0b2c5acb
Mar 29 00&#58;33&#58;14 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; SendConfigAck #1
Mar 29 00&#58;33&#58;14 vpn2 mpd&#58; &#91;N-2&#93;   MAGICNUM 0b2c5acb
Mar 29 00&#58;33&#58;14 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Req-Sent --> Ack-Sent
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; SendConfigReq #2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   ACFCOMP
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   PROTOCOMP
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   MRU 1500
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   MAGICNUM 1a93e62e
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   AUTHPROTO CHAP MSOFTv2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; rec'd Configure Ack #2 &#40;Ack-Sent&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   ACFCOMP
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   PROTOCOMP
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   MRU 1500
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   MAGICNUM 1a93e62e
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   AUTHPROTO CHAP MSOFTv2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Ack-Sent --> Opened
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; auth&#58; peer wants nothing, I want CHAP
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; CHAP&#58; sending CHALLENGE #1 len&#58; 21
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; LayerUp
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; CHAP&#58; rec'd RESPONSE #1 len&#58; 58
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93;   Name&#58; "alex"
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; AUTH&#58; Trying RADIUS
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; RADIUS&#58; Authenticating user 'alex'
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; RADIUS&#58; Rec'd RAD_ACCESS_ACCEPT for user 'alex'
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; AUTH&#58; RADIUS returned&#58; authenticated
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; CHAP&#58; Auth return status&#58; authenticated
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; CHAP&#58; Reply message&#58; S=DA9E96FA4A5DE93E5C84ABC7EE65C75FAD28051B
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; CHAP&#58; sending SUCCESS #1 len&#58; 46
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; authorization successful
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; Matched action 'bundle "C" ""'
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; Creating new bundle using template "C".
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; Bundle&#58; Interface ng0 created
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; Join bundle "C-2"
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; Bundle&#58; Status update&#58; up 1 link, total bandwidth 64000 bps
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; Open event
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; state change Initial --> Starting
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; LayerStart
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; Open event
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Initial --> Starting
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; LayerStart
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; Up event
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; state change Starting --> Req-Sent
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; SendConfigReq #1
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   IPADDR 172.16.200.2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   COMPPROTO VJCOMP, 16 comp. channels, no comp-cid
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; Up event
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; Protocol mppc disabled as useless for this setup
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Starting --> Req-Sent
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; SendConfigReq #1
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; RADIUS&#58; Accounting user 'alex' &#40;Type&#58; 1&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;N-2&#93; RADIUS&#58; Rec'd RAD_ACCOUNTING_RESPONSE for user 'alex'
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; rec'd Configure Request #1 &#40;Req-Sent&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   IPADDR 0.0.0.0
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;     NAKing with 172.16.19.19
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; SendConfigNak #1
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   IPADDR 172.16.19.19
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; rec'd Configure Reject #1 &#40;Req-Sent&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   COMPPROTO VJCOMP, 16 comp. channels, no comp-cid
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; SendConfigReq #2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   IPADDR 172.16.200.2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; rec'd Configure Request #1 &#40;Req-Sent&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; SendConfigAck #1
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Req-Sent --> Ack-Sent
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; rec'd Configure Ack #1 &#40;Ack-Sent&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Ack-Sent --> Opened
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; LayerUp
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; No compression negotiated
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; parameter negotiation failed
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Opened --> Stopping
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; SendTerminateReq #2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; LayerDown
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; rec'd Configure Request #2 &#40;Req-Sent&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   IPADDR 172.16.19.19
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;     172.16.19.19 is OK
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; SendConfigAck #2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   IPADDR 172.16.19.19
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; state change Req-Sent --> Ack-Sent
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; rec'd Configure Ack #2 &#40;Ack-Sent&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   IPADDR 172.16.200.2
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; state change Ack-Sent --> Opened
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; LayerUp
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93;   172.16.200.2 -> 172.16.19.19
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IFACE&#58; No interface to proxy arp on for 172.16.19.19
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IFACE&#58; Up event
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; IFACE&#58; session-timeout limited to 1952257 seconds
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; rec'd Terminate Ack #2 &#40;Stopping&#41;
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Stopping --> Stopped
Mar 29 00&#58;33&#58;15 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; LayerFinish
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; rec'd Terminate Request #2 &#40;Opened&#41;
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Opened --> Stopping
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; Leave bundle "C-2"
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;N-2&#93; RADIUS&#58; Accounting user 'alex' &#40;Type&#58; 2&#41;
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; Bundle&#58; Status update&#58; up 0 links, total bandwidth 9600 bps
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; Close event
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; state change Opened --> Closing
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; SendTerminateReq #3
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; LayerDown
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IFACE&#58; Down event
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; Close event
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Stopped --> Closed
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; Down event
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; LayerFinish
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; Bundle&#58; No NCPs left. Closing links...
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; IPCP&#58; state change Closing --> Initial
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; Down event
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; CCP&#58; state change Closed --> Initial
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;C-2&#93; Bundle&#58; Shutdown
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; SendTerminateAck #3
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; LayerDown
Mar 29 00&#58;34&#58;57 vpn2 mpd&#58; &#91;N-2&#93; RADIUS&#58; Rec'd RAD_ACCOUNTING_RESPONSE for user 'alex'
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Stopping --> Stopped
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; LayerFinish
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; L2TP&#58; Call #0 terminated locally
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; DOWN event
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; Close event
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Stopped --> Closed
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; Down event
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; LCP&#58; state change Closed --> Initial
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; SHUTDOWN event
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; &#91;N-2&#93; Link&#58; Shutdown
Mar 29 00&#58;34&#58;59 vpn2 mpd&#58; L2TP&#58; Control connection 0x28805e08 terminated&#58; 0 &#40;Last session has closed&#41;
Mar 29 00&#58;35&#58;10 vpn2 mpd&#58; L2TP&#58; Control connection 0x28805e08 destroyed

kirush
Сообщения: 699
Зарегистрирован: Пт фев 04, 2005 13:58

Сообщение kirush »

Выручайте :) не могу запустить l2tp авторизацию, может кто то рабочим конфигом поделится?

Oleg1000rud88
Сообщения: 2
Зарегистрирован: Вс апр 15, 2012 06:18
Откуда: Москва
Контактная информация:

Сообщение Oleg1000rud88 »

kirush писал(а):Выручайте :) не могу запустить l2tp авторизацию, может кто то рабочим конфигом поделится?
Пишите в личку. Посторяюсь помочь.

kirush
Сообщения: 699
Зарегистрирован: Пт фев 04, 2005 13:58

Сообщение kirush »

В личку не написать:
"Возможность отправки личных сообщений на этих форумах была отключена"

Закрыто