The only way i find to my vpn client can surf the net is : Set proxy in transparent mode. add pptp_pool to allow use of proxy. So . . . all client connected to the vpn surf the net via vpn tunnel . . . ARG. but . . . it's work.
I'm using SSH sentinel on remote clients in two ways :
- on a computer connected directy to internet by DSL , with no proxy, using virtual IP on SSH and virtual IP + NAT T on the astaro I want to reach by VPN tunnel.
- on a computer belonging to a LAN protected by a firewall (netasq, or astaro). on this computer i use the local proxy on my navigator and virtual ip in ssh. The remote astaro i want to reach by VPN tunnel is always configured with NAT-T and with the same virtual IP.
None PPTP pool used;
All is working fine (VPN tunnel and browsing the internet...).