Tak popořadě - nobsdcomp nepomůže, vyzkoušeno, ani žádný jiný z těch parametrů co jsou zakomentované...
Vyzkoušel jsem přidat ty iptables pravidla -> protocol-unreachable, ale nemá to žádný pro mě viditelný efekt....
Tady je záznam z wireshark, je tam vidět jak se dohodnou na šifrování a pak si pošlou ty konfigurační data - IP, DNS atd. To je čas 538 až 871, pak se už nestane nic a pošle se nějaké Call-Clear-Request a v čase 1220 (

) to server zařízene. Nebo o kus dřív? Tomu úplně nerozumím.
Nějaké GRE pakety se tedy vymění - jestli to dobře chápu je v nich konfigurace, ale pak už nic.
No. Time Source Destination Protocol Length Info
201 3.063047 192.168.99.6 xxx.xxx.xxx.xxx TCP 74 42256→1723 [SYN] Seq=0 Win=29200 Len=0 MSS=1460 SACK_PERM=1 TSval=189466 TSecr=0 WS=128
202 3.066901 xxx.xxx.xxx.xxx 192.168.99.6 TCP 74 1723→42256 [SYN, ACK] Seq=0 Ack=1 Win=8192 Len=0 MSS=1460 WS=256 SACK_PERM=1 TSval=66587157 TSecr=189466
203 3.067031 192.168.99.6 xxx.xxx.xxx.xxx TCP 66 42256→1723 [ACK] Seq=1 Ack=1 Win=29312 Len=0 TSval=189466 TSecr=66587157
204 3.068657 192.168.99.6 xxx.xxx.xxx.xxx PPTP 222 Start-Control-Connection-Request
205 3.072573 xxx.xxx.xxx.xxx 192.168.99.6 PPTP 222 Start-Control-Connection-Reply
206 3.072736 192.168.99.6 xxx.xxx.xxx.xxx TCP 66 42256→1723 [ACK] Seq=157 Ack=157 Win=30336 Len=0 TSval=189467 TSecr=66587158
500 4.069242 192.168.99.6 xxx.xxx.xxx.xxx PPTP 234 Outgoing-Call-Request
501 4.073723 xxx.xxx.xxx.xxx 192.168.99.6 PPTP 98 Outgoing-Call-Reply
502 4.073829 192.168.99.6 xxx.xxx.xxx.xxx TCP 66 42256→1723 [ACK] Seq=325 Ack=189 Win=30336 Len=0 TSval=189567 TSecr=66587258
503 4.074697 192.168.99.6 xxx.xxx.xxx.xxx PPP LCP 66 Configuration Request
504 4.078274 xxx.xxx.xxx.xxx 192.168.99.6 PPP LCP 106 Configuration Request
505 4.078289 xxx.xxx.xxx.xxx 192.168.99.6 PPP LCP 66 Configuration Ack
506 4.079186 192.168.99.6 xxx.xxx.xxx.xxx PPP LCP 69 Configuration Reject
507 4.081651 xxx.xxx.xxx.xxx 192.168.99.6 PPP LCP 95 Configuration Request
508 4.082398 192.168.99.6 xxx.xxx.xxx.xxx PPP LCP 95 Configuration Ack
509 4.084972 xxx.xxx.xxx.xxx 192.168.99.6 PPTP 90 Set-Link-Info
510 4.085108 192.168.99.6 xxx.xxx.xxx.xxx TCP 66 42256→1723 [ACK] Seq=325 Ack=213 Win=30336 Len=0 TSval=189568 TSecr=66587259
511 4.085270 xxx.xxx.xxx.xxx 192.168.99.6 EAP 59 Request, Identity
512 4.085946 192.168.99.6 xxx.xxx.xxx.xxx EAP 68 Response, Identity
513 4.176158 xxx.xxx.xxx.xxx 192.168.99.6 GRE 46 Encapsulated PPP
514 4.399602 xxx.xxx.xxx.xxx 192.168.99.6 EAP 56 Request, TLS EAP (EAP-TLS)
515 4.416784 192.168.99.6 xxx.xxx.xxx.xxx TLSv1 253 Client Hello
516 4.422381 xxx.xxx.xxx.xxx 192.168.99.6 IPv4 1514 Fragmented IP protocol (proto=Generic Routing Encapsulation 47, off=0, ID=0d66) [Reassembled in #517]
517 4.422601 xxx.xxx.xxx.xxx 192.168.99.6 TLSv1 70 Server Hello, Certificate, Server Key Exchange, Certificate Request, Server Hello Done
518 4.423636 192.168.99.6 xxx.xxx.xxx.xxx EAP 60 Response, TLS EAP (EAP-TLS)
519 4.428069 xxx.xxx.xxx.xxx 192.168.99.6 IPv4 1514 Fragmented IP protocol (proto=Generic Routing Encapsulation 47, off=0, ID=0d67) [Reassembled in #520]
520 4.428278 xxx.xxx.xxx.xxx 192.168.99.6 TLSv1 70 Server Hello, Certificate, Server Key Exchange, Certificate Request, Server Hello Done
521 4.429260 192.168.99.6 xxx.xxx.xxx.xxx EAP 60 Response, TLS EAP (EAP-TLS)
522 4.433826 xxx.xxx.xxx.xxx 192.168.99.6 IPv4 1514 Fragmented IP protocol (proto=Generic Routing Encapsulation 47, off=0, ID=0d68) [Reassembled in #523]
523 4.434053 xxx.xxx.xxx.xxx 192.168.99.6 TLSv1 70 Server Hello, Certificate, Server Key Exchange, Certificate Request, Server Hello Done
524 4.435019 192.168.99.6 xxx.xxx.xxx.xxx EAP 60 Response, TLS EAP (EAP-TLS)
525 4.438107 xxx.xxx.xxx.xxx 192.168.99.6 TLSv1 800 Server Hello, Certificate, Server Key Exchange, Certificate Request, Server Hello Done
526 4.537509 192.168.99.6 xxx.xxx.xxx.xxx TLSv1 1450 Certificate, Client Key Exchange, Certificate Verify, Change Cipher Spec, Encrypted Handshake Message
527 4.541665 xxx.xxx.xxx.xxx 192.168.99.6 EAP 60 Request, TLS EAP (EAP-TLS)
528 4.542657 192.168.99.6 xxx.xxx.xxx.xxx TLSv1 1446 Certificate, Client Key Exchange, Certificate Verify, Change Cipher Spec, Encrypted Handshake Message
529 4.547162 xxx.xxx.xxx.xxx 192.168.99.6 EAP 60 Request, TLS EAP (EAP-TLS)
530 4.548296 192.168.99.6 xxx.xxx.xxx.xxx TLSv1 1446 Certificate, Client Key Exchange, Certificate Verify, Change Cipher Spec, Encrypted Handshake Message
531 4.552394 xxx.xxx.xxx.xxx 192.168.99.6 EAP 60 Request, TLS EAP (EAP-TLS)
532 4.553328 192.168.99.6 xxx.xxx.xxx.xxx TLSv1 1446 Certificate, Client Key Exchange, Certificate Verify, Change Cipher Spec, Encrypted Handshake Message
533 4.559427 xxx.xxx.xxx.xxx 192.168.99.6 EAP 60 Request, TLS EAP (EAP-TLS)
534 4.560143 192.168.99.6 xxx.xxx.xxx.xxx TLSv1 220 Certificate, Client Key Exchange, Certificate Verify, Change Cipher Spec, Encrypted Handshake Message
535 4.574649 xxx.xxx.xxx.xxx 192.168.99.6 TLSv1 123 Change Cipher Spec, Encrypted Handshake Message
536 4.578235 192.168.99.6 xxx.xxx.xxx.xxx EAP 60 Response, TLS EAP (EAP-TLS)
537 4.581378 xxx.xxx.xxx.xxx 192.168.99.6 EAP 58 Success
538 4.582308 192.168.99.6 xxx.xxx.xxx.xxx PPP CCP 64 Configuration Request
539 4.584956 xxx.xxx.xxx.xxx 192.168.99.6 PPP CCP 60 Configuration Request
540 4.584973 xxx.xxx.xxx.xxx 192.168.99.6 PPP IPCP 60 Configuration Request
541 4.585300 192.168.99.6 xxx.xxx.xxx.xxx GRE 46 Encapsulated PPP
542 4.585630 192.168.99.6 xxx.xxx.xxx.xxx PPP CCP 60 Configuration Nak
543 4.585826 192.168.99.6 xxx.xxx.xxx.xxx PPP IPCP 54 Termination Ack
544 4.587365 xxx.xxx.xxx.xxx 192.168.99.6 PPP CCP 64 Configuration Ack
545 4.587822 xxx.xxx.xxx.xxx 192.168.99.6 PPP CCP 64 Configuration Request
546 4.588054 192.168.99.6 xxx.xxx.xxx.xxx GRE 46 Encapsulated PPP
547 4.589279 192.168.99.6 xxx.xxx.xxx.xxx PPP CCP 60 Configuration Ack
548 4.589499 192.168.99.6 xxx.xxx.xxx.xxx PPP IPCP 72 Configuration Request
549 4.592930 xxx.xxx.xxx.xxx 192.168.99.6 PPP IPCP 76 Configuration Nak
550 4.593654 192.168.99.6 xxx.xxx.xxx.xxx PPP IPCP 76 Configuration Request
551 4.596120 xxx.xxx.xxx.xxx 192.168.99.6 PPP IPCP 76 Configuration Ack
552 5.096997 192.168.99.6 xxx.xxx.xxx.xxx GRE 46 Encapsulated PPP
870 6.095748 xxx.xxx.xxx.xxx 192.168.99.6 PPP IPCP 60 Configuration Request
871 6.099616 192.168.99.6 xxx.xxx.xxx.xxx PPP IPCP 64 Configuration Ack
872 6.115393 xxx.xxx.xxx.xxx 192.168.99.6 PPTP 82 Call-Clear-Request
873 6.115602 192.168.99.6 xxx.xxx.xxx.xxx TCP 66 42256→1723 [ACK] Seq=325 Ack=229 Win=30336 Len=0 TSval=189771 TSecr=66587462
1220 37.128129 xxx.xxx.xxx.xxx 192.168.99.6 TCP 66 1723→42256 [FIN, ACK] Seq=229 Ack=325 Win=131584 Len=0 TSval=66590563 TSecr=189771
1221 37.128482 192.168.99.6 xxx.xxx.xxx.xxx PPTP 82 Call-Clear-Request
1222 37.128940 192.168.99.6 xxx.xxx.xxx.xxx TCP 66 42256→1723 [FIN, ACK] Seq=341 Ack=230 Win=30336 Len=0 TSval=192873 TSecr=66590563
1223 37.131587 xxx.xxx.xxx.xxx 192.168.99.6 TCP 66 1723→42256 [ACK] Seq=230 Ack=342 Win=131584 Len=0 TSval=66590564 TSecr=192873
Prosímtě
johnyseb, vypadá že do toho vidíš, mohl bych ti poslat i detailnější data, ale mimo veřejnost, kdybys měl čas/ochotu pomoct... ? Jinak i za ten tip s IPTABLES samozřejmě díky.
Nemůže to být nějaký bordel jen v routování? Když všechny svoje zásahy vyhodím, udělá PPPD jen routu
10.100.8.10 0.0.0.0 255.255.255.255 UH 0 0 0 ppp0
což se ni zdá dobře, aby to teklo k tomu endpointu, ale ... nevím.
Nějak nefunguje přihlášení k tomuhle fóru mimochodem...