Networking-Blog

My WordPress Blog

Client PPTP VPN Dialer Setup on Linux (split tunnel)

The first step is to get into “Network connections” and then “Configure VPN”.

One way you can do this is by clicking the desktop icon for networking as shown in the picture.

ubuntu-vpn1

Another way is to go to “System” –> “Preferences” –> “Network Connections”.

ubuntu-vpn0

Once your on the “VPN” tab in the “Network connections” configurations window, click “Add”.

ubuntu-vpn2

On the next window we only need to click “Create”, as the default connection type of PPTP is what we want to use.

ubuntu-vpn3

In the next window give your dialer a name, fill in the gateway with your servers DNS-name or IP address as seen from the internet and fill in the user credentials.

If you have used the “Setting up a VPN (PPTP) server on Debian” guide for the server setup or you are using this client for a DD-WRT PPTP server setup, you also need to enable the MPPE encryption options for authentication.

Click on “Advanced”.

ubuntu-vpn4

On the “Advanced Options” window check the first checkbox for the MPPE option, then the second checkbox to allow stateful encryption and click “OK”.

ubuntu-vpn5

Back on the main window, click the “IPv4 Settings” tab.

ubuntu-vpn6

On the routes configuration window check the checkbox of “Use this connection only for resources on its network”.

ubuntu-vpn7

Activate the VPN connection client by clicking on the “Network connections” icon and selecting it.

ubuntu-vpn8

That’s it, you can now access the resources on the VPN servers side as if you were on the same network while not sacrificing your download speed in the process…

Enjoy :)

Howto: Setup Basic PPTP Linux VPN Server for Microsoft Clients

*Note:  This configuration is based on a Redhat/Fedora installation, but should work the same with other linux distributions.  Some commands may differ.

I needed to setup a VPN server so that I can access some tools that run here from home.
I came across a bunch of hurdles and thought i’d document them here for anyone who needs to do the same.

This will allow MS clients and probably Apple too.
PPTP server uses interface ppp0 is the Point to Point Protocol interface number 0.

Packages Required for PPTP VPN:

Kernel that supports MPPE 128-bit encryption
PPP
PPTPD

Fedora ships out of the box with MPPE and PPP ready to rock.  The only thing I really need to do is add the PPTPD package.

Step 1: Install PPTPD

yum install pptpd

Once yum has installed this package successfully, you will notice that it has created a pptpd.conf file in your /etc directory.  Go ahead and check for it:

ls /etc | grep pptp
pptpd.conf

At this point, you should have a working pptp daemon.  This is a matter of personal preference, but I like to go ahead and start pptpd just to make sure that the service is functioning and that it opens up the PPTP port (1723) on the machine:

[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd:                                            [  OK  ]
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.

If you get this far and the service starts and you get the message “Connected to localhost.” when you telnet to port 1723, you should be right as rain.

Step 2: Configuration Files:

There are three configuration files we need to worrry about.  They are /etc/pptpd.conf, /etc/ppp/options.pptpd, and /etc/sysctl.conf.

Let’s start with /etc/pptpd.conf.  There are three main criteria that we need to worry about, so you will need to edit this file and make sure these entries are in it. Bear in mind that a “#” symbol in front of the lines means that the line in front of the # is disabled.  You do not want this for the following three lines.  Also, the localip and remoteip fields will need to be changed according to your ip addressing scheme. :

option /etc/ppp/options.pptpd

ppp /usr/sbin/pppd

localip 10.20.254.249
remoteip 10.20.254.250-253

In the example above, the first line, “option /etc/ppp/options.pptpd” tells the pptp daemon
where to locate the options.pptpd file which contains various options on how to set up the
pptp tunnel (encryption type, authentication type, and so on).

The second line, “ppp/usr/sbin/pppd” tells the pptp daemon where to find the ppp  daemon.
This is necessary because the pptp daemon will need to initialize the ppp daemon in order for
this all to work. Both daemons work together to create our tunnel.

The final two lines with “localip” and “remoteip” are also quite important.
In your case, localip should be the ip address of your particular linux machine.
The remote ip will be the ip address, or addresses that you will hand out to your mobile VPN clients – similar
to a very simple DHCP scope.
For example, the above entry allows for 10 simultaneous connections of which 192.168.10 will be
the first address given to the remote user.  Just make sure that these addresses are actually available
on your network and not in any other DHCP scope.  *Note: You may use CIDR if you have a particular
subnet that you want to hand remote users, just make sure that your routing can handle it.

Now, on to /etc/ppp/options.pptpd

As stated previously, options.pptpd is concered with how the VPN will authenticate and encrypt.  Below are the options that you actually care about:

name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe

I will go through these briefly.

The first line indicates the name of the daemon.
The 2nd and 3rd lines indicate what type of authentication and what kind of encryption is required.
MSCHAP-v2 is preferred for Microsoft clients.
Mppe-128 bit encryption is also preferred.
The fourth line is optional as you can choose whether or not to give your mobile clients a DNS entry
so that they access resources by name.
The fifth line indicates that each individual session is locked and only accessible by the initial connected party.
This is quite important and should ALWAYS be present.
Sixth line, nobsdcomp, disables BSD type compression, which MS clients tend to have problems with. The last two lines auth and require-mpp just tell the daemon to authenticate the client and require MPPE.

Lastly, /etc/sysctl.conf:

Edit this file and make sure the net.ipv4.ip_forward is set to 1.  This enables ip packet forwarding on the LAN which is required if you expect your VPN users to be able to access any other resources on the network besides the VPN server itself.

net.ipv4.ip_forward = 1

Step 3: Setting up Users:

The users can be set up one of several ways, either through LDAP, MS Active Directory, or /etc/passwd authentication – however, that is outside the realm of this tutorial.  If you did want to do it that way, you would need to modify the above options.pppd file.  The auth in the options.pppd file defaults to the chap-secrets file which we will now modify. The chap-secrets file in the /etc/ppp/ directory.

# client server          secret IP addresses
rich                pptpd         apassword     80.40.0.0/13
geoff              pptpd         apassword     212.219.0.0/14

The above is pretty self explanatory.  Each line will represent one user.  The “*” specifies that any of the allotted ip addresses will be assigned to that particular user.  You could enter in a specific IP address that you would like each particular user to receive upon connection, if necessary.

Step 4: Test and Troubleshoot:

At this point you will want to restart your pptpd service so that it can read your newly edited config files.

/etc/init.d/pptpd stop
/etc/init.d/pptpd start

You will want to set up a vpn connection on either a windows or linux machine just as you
would normally do, and try to connect.  The main output of the attempted connection will
be located in /var/log/messages.  More detailed logging can be found in the pptp logs.
My first connection attempt completely failed and here is the output of /var/log/messages:

Linux PPTP Server IPtables Rules :

You will need to port forward on public facing router pptp tcp port 1723 from the internet to
the server to enable the connection.
( on cisco router)
ip nat inside source static tcp  (local-ip-address-of-server) 1723 interface FastEthernet0/0 1723
!
You will need to allow GRE packets ( udp 47) on public facing router incoming from the internet.
( on cisco router)
ip access-list extended INTERNET
permit gre any any

!
Generic Routing Encapsulation (GRE
) is a tunneling protocol designed to encapsulate a wide
variety of network layer packets inside IP tunneling packets.
GRE protocol cannot inspect non-IP traffic, as above we allow GRE return packets through the public facing router on the incoming firewall rule.
!
You will need to allow pptp port 1723  on the INPUT chain  on linux server.
iptables -I INPUT -d (local-ip-address-of-server) -i eth0 -p tcp -m tcp –dport 1723 -j ACCEPT
!
You will need to allow GRE packets on the OUTPUT chain on linux server
.
iptables -I OUTPUT -s (local-ip-address-of-server) -p gre -j ACCEPT
!
You will need to allow pptp port 1723 packets OUTPUT from server with a SNAT (source-nat) of tcp 1723.
iptables -I OUTPUT -s (local-ip-address-of-server) -p tcp -m tcp –sport 1723 -j ACCEPT

Sumarize Firewall Rules :

Allow GRE-47/pptp-1723 on internet facing router.
Configure a port forward for pptp-1723 to internal lan server ip address.
Allow GRE traffic out from pptp server.
Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any.

PPTP Server is hosting a CIFS share, add iptables rules to allow pptp host 10.20.254.249 access to CIFS share on another interface on server  (192.168.2.4)

PPTP server uses interface ppp0 is the Point to Point Protocol interface number 0.

INPUT CHAIN :

iptables – I INPUT -s 10.20.254.249/32 -d 192.168.2.4/32 -i ppp0 -p tcp -m tcp –dport 139 -j ACCEPT
iptables – I INPUT -s 10.20.254.249/32 -d 192.168.2.4/32 -i ppp0 -p tcp -m tcp –dport 445 -j ACCEPT

OUTPUT CHAIN :

iptables – I OUTPUT -s 192.168.2.4/32 -d 10.20.254.249/32 -p tcp -m tcp –dport 445 -j ACCEPT

Linux Redhat Create Sub-Interface

Need to create a Ethernet Subinterface on the VM :

The IP configurations on the Red Hat distribution of the Linux operating system are stored in the directory /etc/sysconfig/network-scripts/.
Each interface, as well as sub-interface, requires a unique configuration file.

The below example assigns the interface eth0 an IP address of 192.168.1.42 on a class C network with 192.168.1.1 as the gateway.

/etc/sysconfig/network-scripts/ifcfg-eth0:

DEVICE=eth0
IPADDR=192.168.1.42
NETMASK=255.255.255.0
ONBOOT=yes
GATEWAY=192.168.1.1

In order to assign multiple IP addresses on the same interface (eth0), there must be a configuration file for the sub-interface eth0:0 (incrementing as necessary). The below example will add three more IP addresses to the same interface:

/etc/sysconfig/network-scripts/ifcfg-eth0:0:

DEVICE=eth0:0
IPADDR=192.168.1.41
NETMASK=255.255.255.0
ONBOOT=yes

/etc/sysconfig/network-scripts/ifcfg-eth0:1:

DEVICE=eth0:1
IPADDR=192.168.1.44
NETMASK=255.255.255.0
ONBOOT=yes

/etc/sysconfig/network-scripts/ifcfg-eth0:2:

DEVICE=eth0:2
IPADDR=192.168.1.45
NETMASK=255.255.255.0
ONBOOT=yes

Previously Configured Sub-Interface :

# Advanced Micro Devices [AMD] 79c970 [PCnet32 LANCE]
DEVICE=eth0:3
BOOTPROTO=static
ONBOOT=yes
HWADDR=00:0c:29:fa:da:13
IPADDR=
192.168.1.45
NETMASK=255.255.255.0
NETWORK=
192.168.1.0
BROADCAST=192.168.1.253

Note that a gateway statement is not necessary in this file because the same gateway was defined in /etc/sysconfig/network-scripts/ifcfg-eth0.

To update your system’s IP configuration after making changes to the /etc/sysconfig /network-scripts/ directory, execute:

# service network restart
Bring Interfaces UP without restarting network services.

sudo ifup eth0:0
sudo ifup eth0:1
sudo ifup eth0:2
sudo ifup eth0:3

Linux Ubuntu Add Sub-Interface

Ubuntu Sub-interfaces

I have found myself searching the internet for the correct configuration for
Linux subinterfaces.
A subinterface is a division of one physical interface into multiple logical interfaces.

So why would we do that?
!
I use subinterfaces for hosting multiple SSL sites, DSR returns for localhost for my
load balancers, and anything else you would need multiple ips on the same physical interface.

In Ubuntu it is easy to add subinterfaces I have never had to add a temporary subinterface
in Ubuntu but I guess I figure it is easier to just add it to the system and restart networking
.

Here is how to add a Ubuntu subinterface with ifconfig.

Adding a Ubuntu subinterface without restarting networking.

1. Add the interface and ip with one step

$ sudo ifconfig eth0:0 192.168.1.253 netmask 255.255.255.0

2. Turn the ip address up

$ sudo ifconfig eth0:0 up

3.  Check and make sure it is in ifconfig

$ ifconfig -a

eth0      Link encap:Ethernet  HWaddr 00:30:48:28:65:2b
inet addr:192.168.1.5  Bcast:192.168.1.255  Mask:255.255.255.0
inet6 addr: fe80::230:48ff:fe28:652b/64 Scope:Link
UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
RX packets:101278725 errors:10 dropped:0 overruns:0 frame:10
TX packets:96594294 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:3734515707 (3.7 GB)  TX bytes:1773845088 (1.7 GB)

eth0:0    Link encap:Ethernet  HWaddr 00:30:48:28:65:2b
inet addr:192.168.1.253  Bcast:192.168.1.255  Mask:255.255.255.0
UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1

4. Remember the subinterface is gone unless you add it to /etc/network/interfaces.


Adding a Ubuntu subinterface permanently.

Now that you have added the subinterface without restarting networking,
or
rebooting, we need to add the ip address to the configuration file on Ubuntu so the
new ip address will be on the system when you do some upgrades and need to reboot.

1.  Open the /etc/network/interfaces file with your favorite editor

$ sudo vi /etc/network/interfaces

2. Add the following lines below your physical interface to create the subinterface on reboot.

auto eth0:0
iface eth0:0 inet static
address 192.168.1.253
netmask 255.255.255.0

3. You can always add more Ubuntu subinterfaces by changing
eth0:0 to eth0:1 and eth0:2 and so on
.

Here is  and example of my complete /etc/network/interfaces file with Ubuntu subinterfaces.

# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

# The loopback network interface
auto lo
iface lo inet loopback

# The primary network interface
auto eth0
iface eth0 inet static
address 192.168.1.5
netmask 255.255.255.0
network 192.168.1.0
broadcast 192.168.1.255
gateway 192.168.1.1

auto eth0:0
iface eth0:0 inet static
address 66.37.141.237
netmask 255.255.255.0

Linux Transit VM Port Forward

Need forwarding to Telford Internal IP Address – 10.10.1.1
Fixed Internet IP Address – 1.1.1.1

Ports 40000, 41000, 42000, 43000, 44000, 45000, & 46000 need forwarding to 10.10.1.1

Configuration to be Done.

Need to create a Ethernet Subinterface on the VM :

# Advanced Micro Devices [AMD] 79c970 [PCnet32 LANCE]
DEVICE=eth1:3
BOOTPROTO=static
ONBOOT=yes
HWADDR=00:0c:29:fa:da:13
IPADDR=1.1.1.1
NETMASK=255.255.255.0
NETWORK=1.1.1.254
BROADCAST=1.1.1.253
Bring Interface UP :

sudo ifup eth1:3

To View a list of rules with the NAT table :

sudo iptables -vnL -t nat –line-numbers

Need to complete PREROUTING chain in order to DNAT these ports from WAN to destination LAN address :

sudo iptables -t nat -I PREROUTING 1 -d 1.1.1.1 -p tcp –dport 40000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 2 -d 1.1.1.1 -p tcp –dport 41000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 3 -d 1.1.1.1 -p tcp –dport 42000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 4 -d 1.1.1.1 -p tcp –dport 43000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 5 -d 1.1.1.1 -p tcp –dport 44000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 6 -d 1.1.1.1 -p tcp –dport 45000 -j DNAT –to 10.10.1.1
sudo iptables -t nat -I PREROUTING 7 -d 1.1.1.1 -p tcp –dport 46000 -j DNAT –to 10.10.1.1

To summarize this as one rule :

sudo iptables -t nat -I PREROUTING 18 -d 85.234.86.115 -p tcp -m multiport –dport 40000,41000,42000,43000,44000,45000,46000 -j DNAT –to 10.10.1.1

Need to complete POSTROUTING chain in order to SNAT these ports from LAN address to destination Subinterface : :

sudo iptables -t nat -I POSTROUTING 20 -o eth1:3 -s 10.10.1.1 -p tcp -m multiport –dports 40000,41000,42000,43000,44000,45000,46000 -j SNAT –to 1.1.1.1

To Delete a Chain Rule

sudo iptables -t nat -D POSTROUTING 20
sudo iptables -t nat -D PREROUTING 20

Troubleshooting Diagnostics Testing :

From the Internet :

telnet 85.234.86.115 40000

B00m.

How to log in LINUX IPTABLES

Before we get into the iptables rules, lets make sure that what we are doing is going to log.
First lets open up “/etc/syslog.conf” and add this entry

kern.* /var/log/firewall.log

Now restart your syslog daemon.. “/etc/init.d/syslog restart”

sudo iptables -I OUTPUT -j LOG
This means to jump to the LOG chain in iptables.
Now lets say you want your logging to be more verbose.
In iptables we can fix that by adding this entry in the rule.. –log-level 7.
This is the highest level of logging (DEBUG LEVEL).

e.g :

sudo iptables -I OUTPUT -j LOG –log-level 7

Logging

In the  above examples none of the traffic will be logged.
If you would like to log dropped packets to syslog, this would be the quickest way:

iptables -I INPUT 5 -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7
iptables -I OUTPUT 5 -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7

To have packets Denied/Dropped, Place rule at the bottom of Chain or have
it modified for source/destination addresses.

iptables -A INPUT -j block
iptables -A OUTPUT -j block

Using Linux Gentoo:

sudo vi /syslog-ng/syslog-ng.conf

Add these lines :

source kernsrc { file(“/proc/kmsg”); };
destination kern { file(“/var/log/kern.log”); };
destination firewall { file(“/var/log/firewall.log”); };
filter f_firewall { match(“firewall”); };
filter f_kern { facility(kern) and not filter(f_firewall);};
log { source(kernsrc); filter(f_kern); destination(kern); };
log { source(kernsrc); filter(f_firewall); destination(firewall); };