The only way i find to my vpn client can surf the net is : Set proxy in transparent mode. add pptp_pool to allow use of proxy. So . . . all client connected to the vpn surf the net via vpn tunnel . . . ARG. but . . . it's work.
I'm using SSH sentinel on remote clients in two ways :
- on a computer connected directy to internet by DSL , with no proxy, using virtual IP on SSH and virtual IP + NAT T on the astaro I want to reach by VPN tunnel.
- on a computer belonging to a LAN protected by a firewall (netasq, or astaro). on this computer i use the local proxy on my navigator and virtual ip in ssh. The remote astaro i want to reach by VPN tunnel is always configured with NAT-T and with the same virtual IP.
None PPTP pool used;
All is working fine (VPN tunnel and browsing the internet...).
I'm using SSH sentinel on remote clients in two ways :
- on a computer connected directy to internet by DSL , with no proxy, using virtual IP on SSH and virtual IP + NAT T on the astaro I want to reach by VPN tunnel.
- on a computer belonging to a LAN protected by a firewall (netasq, or astaro). on this computer i use the local proxy on my navigator and virtual ip in ssh. The remote astaro i want to reach by VPN tunnel is always configured with NAT-T and with the same virtual IP.
None PPTP pool used;
All is working fine (VPN tunnel and browsing the internet...).
I've make some further tests with SSH Sentinel, ASTARO and others firewalls/VPN box.
The problem (unable to access directly to internet from the client when VPN is established) seems to come from a bad configuration of Virutal, either on Sentinel and/or Firewall.
If you're using SSH sentinel to establish a VPN tunnel and want to access internet directlly (without having to use the remote proxy), just uncheck the option "deny split tunneling" in the advanced parameters of the VPN tunnel properties in sentinel.