L2TP and PPTP vpn clients connect to the VPN server, no internal networkin
both types of connections (l2tp and pptp) connect and authenticate to the server. both types can not access machines on the lan via the vpn server.
going to an internal webserver gives times, ssh connections to other servers time out. no hint in the client logs (I have the client firewall logging all packets)
basic lay out is main dns is xxx.xxx.242.13 (subnet1, router interface 242.1)
vpn server and 2nd dns server is xxx.xxx.242.130 (subnet2, router interface 242.129)
vpn address range xxx.xxx.242.131 through xxx.xxx.242.136
here's a client connection from the vpnd.log for a l2tp connection (date stamp removed, actually names and numbers obscurred)
2010-01-08 15:10:42 PST Incoming call... Address given to client = xxx.xxx.242.132
Directory Services Authentication plugin initialized
Directory Services Authorization plugin initialized
L2TP incoming call in progress from 'xxx.xxx.41.248'...
L2TP received SCCRQ
L2TP sent SCCRP
L2TP received SCCCN
L2TP received ICRQ
L2TP sent ICRP
L2TP received ICCN
L2TP connection established.
using link 1
Using interface ppp1
Connect: ppp1 <--> socket[34:18]
sent [LCP ConfReq id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0x1b57f351> <pcomp> <accomp>]
rcvd [LCP ConfReq id=0x1 <asyncmap 0x0> <magic 0x5afd4ba7> <pcomp> <accomp>]
lcp_reqci: returning CONFACK.
sent [LCP ConfAck id=0x1 <asyncmap 0x0> <magic 0x5afd4ba7> <pcomp> <accomp>]
Fri Jan 8 15:10:42 2010 : rcvd [LCP ConfAck id=0x1 <asyncmap 0x0> <auth chap MS-v2> <magic 0x1b57f351> <pcomp> <accomp>]
sent [LCP EchoReq id=0x0 magic=0x1b57f351]
sent [CHAP Challenge id=0x12 <ed2ccdfb37378cf70268ff62fe433da0>, name = "VPNservername.FQDN"]
rcvd [LCP EchoReq id=0x0 magic=0x5afd4ba7]
sent [LCP EchoRep id=0x0 magic=0x1b57f351]
rcvd [LCP EchoRep id=0x0 magic=0x5afd4ba7]
rcvd [CHAP Response id=0x12 <ba15b48bbba55ba0dbeb83a847e1a1f600000000000000006dcde615a7a7e08538dc4d00dd851c 195be941d6c763c85b00>, name = "UserName"]
sent [CHAP Success id=0x12 "S=6AB5AFD4706E4CF32F1128709DEBCCC04C28F453 M=Access granted"]
CHAP peer authentication succeeded for UserName
DSAccessControl plugin: User 'UserName' authorized for access
sent [IPCP ConfReq id=0x1 <addr xxx.xxx.242.130>]
sent [ACSCP] 01 01 00 04
rcvd [IPCP ConfReq id=0x1 <addr 0.0.0.0> <ms-dns1 0.0.0.0> <ms-dns3 0.0.0.0>]
ipcp: returning Configure-NAK
sent [IPCP ConfNak id=0x1 <addr xxx.xxx.242.132> <ms-dns1 xxx.xxx.242.130> <ms-dns3 xxx.xxx.242.13>]
rcvd [ACSCP] 01 01 00 10 01 06 00 00 00 01 02 06 00 00 00 01
sent [ACSCP] 02 01 00 10 01 06 00 00 00 01 02 06 00 00 00 01
rcvd [IPCP ConfAck id=0x1 <addr xxx.xxx.242.130>]
rcvd [ACSCP] 02 01 00 04
sent [ACSP data]
02 00 00 1f 00 0b 00 00 00 00 00 00 00 11 65 61 '..............su'
72 74 68 6b 61 6d 2e 75 63 73 64 2e 65 64 75 'bdomain.domain.edu'
sent [ACSP data]
01 00 00 14 00 0b 00 00 84 ef f2 81 ff ff ff 80 '................'
00 01 00 00 '....'
rcvd [IPCP ConfReq id=0x2 <addr xxx.xxx.242.132> <ms-dns1 xxx.xxx.242.130> <ms-dns3 xxx.xxx.242.13>]
ipcp: returning Configure-ACK
sent [IPCP ConfAck id=0x2 <addr xxx.xxx.242.132> <ms-dns1 xxx.xxx.242.130> <ms-dns3 xxx.xxx.242.13>]
ipcp: up
found interface en0 for proxy arp
local IP address xxx.xxx.242.130
remote IP address xxx.xxx.242.132
rcvd [ACSP data]
02 00 00 08 00 04 00 00 '........'
rcvd [ACSP data]
01 00 00 08 00 04 00 00 '........'
after a l2tp connection is made the client shows:
taz-laptop:~ localcnhn$ ifconfig
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x1
inet 127.0.0.1 netmask 0xff000000
inet6 ::1 prefixlen 128
gif0: flags=8010<POINTOPOINT,MULTICAST> mtu 1280
stf0: flags=0 mtu 1280
en0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
ether 00:25:4b:d4:40:7c
media: autoselect status: inactive
supported media: none autoselect 10baseT/UTP <half-duplex> 10baseT/UTP <full-duplex> 10baseT/UTP <full-duplex,flow-control> 10baseT/UTP <full-duplex,hw-loopback> 100baseTX <half-duplex> 100baseTX <full-duplex> 100baseTX <full-duplex,flow-control> 100baseTX <full-duplex,hw-loopback> 1000baseT <full-duplex> 1000baseT <full-duplex,flow-control> 1000baseT <full-duplex,hw-loopback>
fw0: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 4078
lladdr 00:25:4b:ff:fe:d4:40:7c
media: autoselect <full-duplex> status: inactive
supported media: autoselect <full-duplex>
en1: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1500
inet6 fe80::226:8ff:fede:3279%en1 prefixlen 64 scopeid 0x6
inet xx2.xx2.41.248 netmask 0xfffff000 broadcast xx2.xx2.47.255
ether 00:26:08:de:32:79
media: autoselect status: active
supported media: autoselect
ppp0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1280
inet xxx.xxx.242.132 --> xxx.xxx.242.130 netmask 0xffff0000
with the VPN gateway (as seen in System preferences/Networking as being xxx.xxx.242.130 (not the actual lan gateway of xxx.xxx.242.129) and no subnet mask. this might be fine but I don't know VPN structures well enough to comment.
So any thoughts why I can connect (which takes firewall issues out of the way) to the VPN server but can't get internal routing?
other information
the vpn service ->Setting ->client information
Dns Servers
xxx.xxx.242.13
xxx.xxx.242.130
search domains
mysubdomain.domain.edu
network routing definition (this corresponds to the subnet gateway/netmask of a regular client on the subnet as I have it setup)
xxx.xxx.242.129 255.255.255.128 private
macbook pro 13", Mac OS X (10.5.8), lots