Что то у меня не работает со строкой в pf.conf .
scrub all random-id max-mss 1400 min-ttl 128 fragment reassemble
Пинги ходят - http и ftp нет.
Вот ввесь pf.conf
set limit states 128000
set optimization aggressive
scrub all random-id max-mss 1400 min-ttl 128 fragment reassemble
nat pass on vr1 from 172.16.0.0/16 to any -> vr1
nat pass on vr1 from 192.168.0.0/16 to any -> vr1
Вернее не работает только vpn на mpd5
Строка
set iface enable tcpmssfix
в mpd.conf комментирована
startup:
set user admin hardpass6
set console self 127.0.0.1 5005
set console open
set web self 0.0.0.0 5006
set web open
default:
load pppoe_server
load pptp_server
pppoe_server:
create bundle template B
set ipcp ranges 172.16.2.254/32 127.0.0.2/32
set ipcp dns 10.0.0.1 10.0.0.6
set ccp yes mppc
set mppc yes e40
set mppc yes e56
set mppc yes e128
set mppc yes stateless
set ecp disable dese-bis dese-old
create link template common pppoe
set link enable multilink
set link action bundle B
set link disable chap pap eap
set link enable pap
load radius
set pppoe service "*"
create link template vr0 common
set link max-children 1000
set pppoe iface vr0
set link enable incoming
pptp_server:
create bundle template P
# set iface enable tcpmssfix
set ippool add pool1 172.16.0.1 172.16.1.254
set ipcp yes vjcomp
set ipcp ranges 172.16.2.254/32 ippool pool1
set ipcp dns 127.0.0.1
set bundle enable compression
set ccp yes mppc
set mppc yes e40
set mppc yes e128
set mppc yes stateless
set ecp disable dese-bis dese-old
create link template L pptp
set link enable multilink
set link yes acfcomp protocomp
set link action bundle P
set link disable chap pap eap
set link enable chap-msv2 chap
set link keep-alive 10 60
load radius
set link enable incoming
set link mtu 1500
# set iface mtu 1490
# set link mtu 1500
set iface enable proxy-arp
set iface idle 1800
set pptp self 192.168.2.254
radius:
set radius server localhost hardpass5 1812 1813
set radius retries 3
set radius timeout 3
set radius me 127.0.0.1
set auth acct-update 45
set auth enable radius-auth
set auth enable radius-acct
set radius enable message-authentic
При этом pppoe и через авторизатор работает без проблем.
Может чего лишнего в mpd.conf вписал?
Поправте.