I cannot get a VPN connection to my Sophos UTM9 using PPTP. I followed the PDF guide from Sophos, but no luck. I only need a simple PPTP VPN in using local authentication. Does anyone have any advice?
Background info:
- Fibre to the home via National Broadband Network (NBN)
- ISP is Optus
- Dynamic WAN Address
- Utilising DynDNS
- Internal IP address range is 10.0.0.x
- UTM IP address is 10.0.0.1
- UTM is directly connected to the NBN Network Termination Device (NTD). No modem/router is in-between the UTM and the outside world. UTM acts as the router and connects to the internet using IPOE.
- I am able to make a successful VPN connection to a QNAP when using a MyNet 900 Western Digital router in place of the UTM.
Firewall Rules
Internal (Network) -> Any
---
1900
5351
Cisco VPN Ports
GRE
IPsec - AH
IPsec - ESP
IPsec - IKE
IPsec - NAT-T
PPTP
SSDP 61521
UDP 5353
VPN Protocols
WebAdmin
NTP
RTRR
RTSP
DNS
Email Messaging
File Transfer
Terminal Applications
Web Surfing
Masquerading Rule
Network: Network (Internal)
Position: 1
Interface: External (WAN)
Use address >
PPTP- Remote access settings
Authentication via: Local
Users and Groups: admin
Assign IP address by: IP address pool
Pool Network: VPN Pool (PPTP)
Sophos Logs - when a client attempts to connect
2015:01:06-08:10:10 filewall pptpd[12069]: MGR: Launching /usr/sbin/pptpctrl to handle client
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: local address = 10.242.1.1
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: remote address = 10.242.1.2
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Client 121.127.216.154 control connection started
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Received PPTP Control Message (type: 1)
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Made a START CTRL CONN RPLY packet
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: I wrote 156 bytes to the client.
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Sent packet to client
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Received PPTP Control Message (type: 7)
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Set parameters to 100000000 maxbps, 64 window size
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Made a OUT CALL RPLY packet
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Starting call (launching pppd, opening GRE)
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: pty_fd = 6
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: tty_fd = 7
2015:01:06-08:10:10 filewall pptpd[12070]: CTRL (PPPD Launcher): program binary = /usr/sbin/pppd
2015:01:06-08:10:10 filewall pptpd[12070]: CTRL (PPPD Launcher): local address = 10.242.1.1
2015:01:06-08:10:10 filewall pptpd[12070]: CTRL (PPPD Launcher): remote address = 10.242.1.2
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: I wrote 32 bytes to the client.
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Sent packet to client
2015:01:06-08:10:10 filewall pppd-pptp[12070]: Plugin aua.so loaded.
2015:01:06-08:10:10 filewall pppd-pptp[12070]: AUA plugin initialized.
2015:01:06-08:10:10 filewall pppd-pptp[12070]: pppd 2.4.5 started by (unknown), uid 0
2015:01:06-08:10:10 filewall pppd-pptp[12070]: using channel 6
2015:01:06-08:10:10 filewall pppd-pptp[12070]: Starting negotiation on /dev/pts/0
2015:01:06-08:10:10 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:10 filewall pptpd[12069]: GRE: Bad checksum from pppd.
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Received PPTP Control Message (type: 15)
2015:01:06-08:10:10 filewall pptpd[12069]: CTRL: Got a SET LINK INFO packet with standard ACCMs
2015:01:06-08:10:13 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:16 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:19 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:22 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:25 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:28 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:31 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:34 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:37 filewall pppd-pptp[12070]: sent [LCP ConfReq id=0x1 ]
2015:01:06-08:10:40 filewall pppd-pptp[12070]: LCP: timeout sending Config-Requests
2015:01:06-08:10:40 filewall pppd-pptp[12070]: Connection terminated.
2015:01:06-08:10:40 filewall pppd-pptp[12070]: Modem hangup
2015:01:06-08:10:40 filewall pppd-pptp[12070]: Exit.
2015:01:06-08:10:40 filewall pptpd[12069]: GRE: read(fd=6,buffer=805a540,len=8196) from PTY failed: status = -1 error = Input/output error, usually caused by unexpected termination of pppd, check option syntax and pppd logs
2015:01:06-08:10:40 filewall pptpd[12069]: CTRL: PTY read or GRE write failed (pty,gre)=(6,7)
2015:01:06-08:10:40 filewall pptpd[12069]: CTRL: Reaping child PPP[12070]
2015:01:06-08:10:40 filewall pptpd[12069]: CTRL: Client 121.127.216.154 control connection finished
2015:01:06-08:10:40 filewall pptpd[12069]: CTRL: Exiting now
2015:01:06-08:10:40 filewall pptpd[11222]: MGR: Reaped child 12069
This thread was automatically locked due to age.