Networking-Blog

My WordPress Blog

Simplify Linux PPTP Server Configuration

yum install pptpd
apt-get pptpd

At this point, you should have a working pptp daemon.
This is a matter of personal preference, but I like to go ahead and start pptpd just to
make sure that the service is functioning and that it opens up the

PPTP port (1723) on the machine:

[user@hostname ~]# /etc/init.d/pptpd start
Starting pptpd:                                            [  OK  ]
!
[user@hostname ~]# telnet localhost 1723
Trying 127.0.0.1…
Connected to localhost.
Escape character is ‘^]’.

3 configuration files we need to worrry about.  They are :

/etc/pptpd.conf
/etc/ppp/options.pptpd

/etc/sysctl.conf

!

Let’s start with /etc/pptpd.conf

edit file :
nano /etc/pptpd.conf

# Currently using Microsoft Client Profile:
option /etc/ppp/MSpptpd-options

# Use linux client profile:
#option /etc/ppp/LXpptpd-options

#       Turns on (more) debugging to syslog
#debug
logwtmp
speed 57600

# Specifies the local and remote IP address ranges.
localip 10.20.254.254
# listen 10.20.254.254
# remoteip 10.10.10.249-253

!

Now, on to /etc/ppp/options.pptpd

As stated previously, options.pptpd is concered with how the VPN will authenticate
and encrypt.  Below are the options that you actually care about
:

name pptpd
require-mschap-v2
require-mppe-128
ms-dns 192.168.1.73
lock
nobsdcomp
auth
require-mppe
noipx ## you don’t need IPX
mtu 1490 ## may help your linux client from disconnecting
mru 1490
## may help your linux client from disconnecting

!

Lastly, /etc/sysctl.conf :

Edit this file and make sure the net.ipv4.ip_forward is set to 1.
This enables ip packet forwarding on the LAN which is required if you expect your
VPN users to be able to access any other resources on the network besides the
VPN server itself.

net.ipv4.ip_forward = 1

Setting up Users :

The chap-secrets file in the /etc/ppp/ directory.
vi /etc/ppp/chap-secrets

# client        server secret           IP addresses
rich              pptpd         apassword     80.40.0.0/13
geoff             pptpd         apassword     212.219.0.0/14

Test and Troubleshoot
:

/etc/init.d/pptpd stop
/etc/init.d/pptpd start

Sumarize Firewall Rules :

1. Allow GRE-47/pptp-1723 on internet facing router.
2. Configure a port forward for pptp-1723 to internal lan server ip address.
3. Allow GRE traffic out from pptp server.
4. Allow pptp tcp port 1723 out from pptp server with a source nat of 1723 to remote host or any
.

Client PPTP VPN Dialer Setup on Win7 (split tunnel)

PPTP VPN Dialer Setup on Win7 (split tunnel)

We will create a regular VPN dialer with one note worthy exception, that we will set the system to NOT use it as the “Default Gateway” when connected.

Skipping this step will limit the connecting computer’s surfing speed to the VPN server’s upload speed (usually slow) because all of it’s traffic would be routed through the VPN connection and that’s not what we want.

We need to start the connection wizard, so we will go to the “Network and Sharing Center”.

Click the network icon in the system tray and then “Open Network and Sharing Center”

win7-vpn1

In the Network center click on “Set up a new connection or network”.

win7-vpn2
Select “Connect to a workplace” and then “Next”.
win7-vpn3
Click on the first option of “Use my Internet connection (VPN)”.

win7-vpn4
Set the address of your VPN server as seen from the internet either by DNS-name or IP.

win7-vpn5
Even though it won’t connect now because we stil need to go into the dialer’s properties, Set the username and password and hit connect.

win7-vpn6
After the connection will fails to connect (that’s normal), click on “Set up the connection anyway”.

win7-vpn7
Back in the “Network Center”, click on “Change adapter settings”.

win7-vpn8
Find the dialer we have just created, right click it and select “Properties”.

win7-vpn9

While its optional, for a faster connecting dialer, set the “type” of VPN to PPTP under “the “Security” tab.

Go to the “Networking” tab, select the IPv4 protocol and go into it’s properties.

win7-vpn10a

In the next window, click “Advance” without changing anything else.

win7-vpn11

On the next window, uncheck the “Use default gateway on remote network” option.

win7-vpn12

Now enter the connection’s credentials as you set them on the server and connect.

win7-vpn13

That’s it, you should now be able to access all the computers on your network from the win7

Client PPTP VPN Dialer Setup on XP (split tunnel)

PPTP VPN Dialer Setup on XP (split tunnel)

We will create a regular VPN dialer with one note worthy exception, that we will set the system to NOT use it as the “Default Gateway” when connected.

Skipping this step will limit the connecting computer’s surfing speed to the VPN server’s upload speed (usually slow) because all of it’s traffic would be routed through the VPN connection and that’s not what we want.

We need to start the connection wizard, so we will go to control panel.

Go to “Start” and then “Control Panel”.

xp-vpn01

*If your system is setup with the “Classic Start Menu” you need to just point on the “Control Panel” icon and then select “Network Connections”.

In “Control Panel” double click “Network Connections”.

xp-vpn02

Double click “New Connection wizard”.

xp-vpn03

In the “New Connection wizard” welcome screen click “Next”.

xp-vpn04

Select the “Connect to the network at my workspace” option and then “Next”.

xp-vpn05

Select the “Virtual Private Network connection” option and then “Next”.

xp-vpn06

Give a name to the VPN connection.

xp-vpn07

Type in the name of your VPN servers DNS-name or IP address as seen from the Internet.

xp-vpn08

Optionally You may choose to “Add a shortcut to the desktop” and “Finish”.

xp-vpn09

Now comes the tricky part, it is vitally important you do NOT try to connect now and go into the dialer’s “Properties”.

xp-vpn10

Go to the networking tab and change the “Type of VPN” to “PPTP VPN” as shown in the picture below (this is optional but will shorten the time it takes to connect) then go into “Properties”.

xp-vpn11

On the next window go into “Advance” without changing anything else.

xp-vpn12

On the next window, uncheck the “Use default gateway on remote network” option.

xp-vpn13

Now enter the connection’s credentials as you set them on the server and connect.

xp-vpn14

That’s it, you should now be able to access all the computers on your network from the XP client… Enjoy.

Exchange Services Restart Script

@echo off

net stop “Microsoft Exchange Information Store”
net stop “Microsoft Exchange Information Store”
net stop “Microsoft Exchange MTA Stacks”
net stop “Microsoft Exchange Management”
net stop “Microsoft Exchange System Attendant”
net start “Microsoft Exchange Information Store”
net start “Microsoft Exchange Information Store”
net start “Microsoft Exchange MTA Stacks”
net start “Microsoft Exchange Management”
net start “Microsoft Exchange System Attendant”

save as .bat file.

Windows MTU Ping Test

MTU Ping Test

A series of ping tests using the command, ping www.expedient.net -f -l xxxx, where xxxx is the packet size, can be used to determine the optimal MTU for your connection.

  1. Go to Start and select Run.
  2. Type in cmd (Windows 2000/XP) or command (Windows 98/ME) into the Open: field. Hit the enter key or click OK. The DOS prompt should open.
  3. At the DOS prompt, type in ping www.expedient.net -f -l 1492 and hit the Enter key.
  4. Note the results above indicate that the packet needs to be fragmented. Lower the size the packet in increments of +/-10 (e.g. 1472, 1462, 1440, 1400) until you have a packet size that does not fragment.
  5. Begin increasing the packet size from this number in small increments until you find the largest size that does not fragment. Add 28 to that number (IP/ICMP headers) to get the optimal MTU setting. For example, if the largest packet size from ping tests is 1462, add 28 to 1462 to get a total of 1490 which is the optimal MTU setting.
  6. Change the MTU using DrTCP or editing the registry. See MTU Settings for further information.

Windows MTU

MTU in more detail:

The MTU setting is a definition of how much data you can transmit in one go before it has to be cut-up or fragmented. Every connection has a limit and can be determined using a simple command in DOS.

The value you should use for your MTU setting is dependant on the MTU value for your ISP since all packets (data) will be travelling through their servers.

To determine the maximum MTU value for your ISP, open a DOS window and type :

ping -f -l [packetsize] [www.your_isp_url.com]

Where [packetsize] is the amount of data you want to send (range is 0 – 1500) and [www.your_isp_url.com] is the url of your ISP.

Your ISP’s MTU is determined from the larest packetsize value that does not return the error “Packet needs to be fragmented but DF set” -28 (20 bytes for the IP and 8 bytes for the ICMP header). This is dependant on how the server is configired, but essentially the result is the same.

For example:

C:WINDOWS>ping -f -l 1472 192.168.1.10

Pinging 192.168.1.10 with 1472 bytes of data:

Reply from 192.168.1.10: bytes=1472 time=2ms TTL=128
Reply from 192.168.1.10: bytes=1472 time=1ms TTL=128
Reply from 192.168.1.10: bytes=1472 time=1ms TTL=128
Reply from 192.168.1.10: bytes=1472 time=1ms TTL=128

Ping statistics for 192.168.1.10:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 2ms, Average = 1ms

The maximum packet size I could send to my gateway system without it fragmenting was 1472. This means that an MTU value of 1500 is fine for my ethernet connection (1472 + 28 = 1500).

As you can see from the example above, you can determine MTU value for you LAN systems also, as this is dependant on the potential bottle neck that is the gateway system. All packets have to pass through that, so the MTU value for your gateway limits the MTU value for your LAN systems.

Summary:

What are RWIN (TCP Receive Window) and MTU?

What is Rwin?

RWIN (or TCP receive window) is the amount of data that your PC can accept without acknowledging the user.
When a sender sends a packet to the user, it requires an acknowledgement from the receiving system. If this ACK is not received, it will wait for a certain amount of time, and then retransmit. This is how TCP is made reliable.
This start-stop process slows down transmission, but to enable a speedier process, you can set the size of the receiving window so as to sustain a continuous data transfer.
By default, this window is too small for many types of DSL and Cable (8192 for Windows 95/98/98SE/NT and 16384 for Windows ME/2000).
Increasing the Rwin setting, will allow more information to be transferred non-stop, up to a point, and then after this point, no difference will be noticed for the particular connection. The point will vary depending on bandwidth * delay. This is why you should allocate more than you actually need. I use a value of 65535.

What is MTU?

MTU is short for Maximum Transmission Unit, the largest physical packet size, measured in bytes, that a network can transmit. Any messages larger than the MTU are divided into smaller packet before being sent.
In order to transmit the most amount in one go, you should set your MTU to a high value. I use a value of 1500.
If your MTU is low, then it will take more packets to transmit the same amount of data as a higher valued MTU, thus taking more time.

How do I use DrTCP and what does it do?

Firstly, I would like to start by explaining that Dr TCP is not a patch… it is purely a shortcut to registry editing. It does nothing without user intervention.

All information has been grabbed from www.dslreports.com and assumes that you are using Win98/98SE/ME/2000.
Dr. TCP

TCP Receive Window: This is where you set the Rwin. This is the single most important tweak, and raising the value from the Windows default will greatly improve download speeds. My Rwin is set to 65535.

Windows Scaling: 65535 is the highest value that you can set your Rwin to, without having to use windows scaling. Scaling is needed to enter any number higher than 65535. Most users do not need a higher Rwin that 65535, and so I recommend that this setting be set to default ( off).

Time Stamping: This setting may or may not improve performance. If you have a line where latency varies a lot, time stamping may be beneficial…….experiment with it to make sure. I have my setting at default ( off).

Selective Acks: This improves the speed of lines that tend to lose packets (packet loss), by re-transmitting only packets that were lost, if any. I have my setting at default ( on).

Path MTU Discovery: This automatically sets your MTU to suit the type of line that you have (dial-up or broadband). The highest MTU that you can set is 1500. I have mine set to default ( on).

Black Hole Detection: This discovers routers on the web that cause MTU Discovery to work sub-optimally. I have mine set to default ( off).

Max. Duplicate ACKs: This allows for faster re-transmission of packets when lost. I leave this setting blank. (blank = 3 for Win98/98SE/ME and blank = 2 for Win2000).

TTL: Time To Live is the amount of hops (servers) that a transmission packet will take before all packets are lost. If you were receiving packets from 20 hops away, and your TTL was set to 19 or less, then all packets would be lost before they reach you. I leave this setting blank (blank = 128 in Win98/98SE/ME/2000).

Adapter Settings: This is where you set your MTU. I have mine set to 1500 for both NIC and Dial-up.

ICS Settings: If you use Internet Connection Sharing (a Microsoft program), then you should set the ICS MTU to the same as that of the PC. This is grayed out if ICS is not being used.

When you are happy with your settings, you need to hit the Apply tab (you may need to hit tab to highlight it). Next click on Exit and then reboot the PC. A reboot is necessary to activate the settings.

An ADSL connection into your premises (office or home) is technically a dedicated line between you and your telephone exchange. However, from your telephone exchange to the ISP’s network, your data would be traveling over a network that is shared between you and other ADSL users.

The speed that you would get would fluctuate depending upon how many users are connected to the network (“contending” for the bandwidth available) at any point in time.

The contention ratio reflects the amount of bandwidth actually available to all the customers versus the maximum bandwidth all of the customers could attempt to use at the same time.

Each Pipe carries a 10Mb capacity, this is the contended bandwidth, it’s not 50 people connected to a 512K pipe. It 50 people connected to a 10Mb pipe.

A contention ratio of 1 would mean that you would always be able to send or receive at the maximum data rate because there is no other user sharing the bandwidth with you, a contention ratio of 50 means that it is possible that you can only send or receive at 1/50th of the pipe capacity because you are sharing the bandwidth with 50 other people.

If you do the sums :

10,000,000 / 50 = 200,000

So the worst-case scenario would be 200K/sec connection.

Statistically, most users do not use their full bandwidth most of the time, so the worst case seldom if ever occurs. The general rule is: the lower the contention ratio, the more likely you are to continue to get fast throughput during busy times. However, because of the “bursty” nature of Internet traffic, it is unlikely that the worst-case scenario will come about.

Windows Clear Cached Cedentials

 

So, to clear cached credentials on a Windows-based computer do the following steps:

1. Open Command Prompt.
2. Type the command:  rundll32.exe keymgr.dll, KRShowKeyMgr
3. When the Stored User Names and Passwords dialog box appears, select the information you want
deleted and press the Remove button.
4. Press the Close button when you are finished.

Windows XP TCP Tuning

Increase Keep-Alive Time-Out for safety connection

The default TCP keepalive timer in Windows is 7200000 ms or 2 hours. This can cause problems if a connection goes down unexpectedly, the Windows PC may wait between 4 and 6 hours before dropping it’s side of the connection so it can be re-established.

A more standard value for the keepalive is 60000 ms or 1 minute. This can be changed by modifying a value in the Windows registry.
To edit the NT/2000/XP registry to set the TCP Keepalive timeout to 60 seconds use the following procedure:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesTCPIPParameters

1. If one of the keys is not KeepAliveTime, in the Edit menu choose New>DWORD Value
2. Name the new key KeepAliveTime
3. Double click on the new KeepAliveTime DWORD entry
4. Enter the Value data ea60 (Hex) or 60000 (Decimal) and click OK
5. Exit regedit
6. Reboot the PC

This will set the TCP keepalive value to 60000 milliseconds, 1 minute. The hex value ea60 and the decimal value 60000 are equivalent.

KeepAliveTime 60 (seconds)
This can cause problems if a connection goes down unexpectedly, the Windows PC may wait between 4 and 6 hours before dropping it’s side of the connection so it can be re-established.

TcpMaxDataRetranmission 5 (seconds)
This key determines how many times TCP retransmits an unacknowledged data segment on an existing connection.

KeepAliveInterval 1 (second)
This key determines how often TCP repeats keep-alive transmissions when no response is received.

DefaultTTL = 128
The TTL value in the registry specifies the number of hops that a TCP/IP request can travel through before timing out. The default TTL is 32. If you ever have trouble connecting to a host that is more than 32 hops away, you can try increasing the TTL to 128.

EnablePMTUDiscovery
Enabling the setting causes TCP to attempt to discover the Maximum Transmission Unit (MTU or largest packet size) over the path to a remote host. By discovering the Path MTU and limiting TCP segments to this size, TCP can eliminate fragmentation at routers along the path that connect networks with different MTUs.

System Key: [HKEY_LOCAL_MACHINESystemCurrentControlSetServicesTcpipParameters]
Value Name: EnablePMTUDiscovery
Data Type: REG_DWORD (DWORD Value)
Value Data: (0 = false, 1 = true)

TcpMaxDupAcks
This parameter determines the number of duplicate ACKs that must be received for the same sequence number of sent data before “fast retransmit” is triggered to resend the segment that has been dropped in transit.

HKLMSYSTEMCurrentControlSetServicesTcpipParameters
TcpMaxDupAcks=”2″ (DWORD – range 1-3, recommended setting is 2).

MTU = 1500
This parameter specifies the Maximum Transmission Unit (MTU) for a network interface. By optimizing the MTU setting you can gain substantial network performance increases, especially when using dial-up modem connections.
MTU stands for Maximum Transmission Unit and in basic terms, it defines the maximum size of a packet that can be transferred in one frame over a network.

Create a new DWORD value, or modify the existing value, called “MTU” and set it to equal the required MTU size in decimal.

Recommended Values

•576 – Dial-up Connections
•1492 – PPPoE Broadband Connections
•1500 – Ethernet, DSL and Cable Broadband Connections

Restart Windows for the change to take effect.

Web-Browsing:

KeepAliveTimeout 120 (seconds)
By default, IE will reuse an HTTP connection unless it’s been idle for longer than 1 minute. You can adjust this keep-alive timeout setting by performing the following steps:

1.Start a registry editor (e.g., regedit.exe).
2.Navigate to the HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionInternet Settings registry subkey.
3.From the Edit menu, select New, DWORD Value.
4.Enter the name KeepAliveTimeout, then press Enter.
5.Double-click the new value, set it to the number of milliseconds in the new timeout, then click OK.
6.Close the registry editor.
7.Restart the computer for the changes to take effect.

Microsoft Windows Update Links

http://windowsupdate.microsoft.com
http://*.windowsupdate.microsoft.com
https://*.windowsupdate.microsoft.com
http://*.update.microsoft.com
https://*.update.microsoft.com
http://*.windowsupdate.com
http://download.windowsupdate.com
http://download.microsoft.com
http://*.download.windowsupdate.com
http://test.stats.update.microsoft.com
http://ntservicepack.microsoft.com

WSUS Server :

1. How to force an AU Client to detect and download approved updates from a WSUS Server?

A. Run this command from Command prompt at the AU client :

wuauclt.exe /detectnow

2. Verify if the AU Client is checking in with WSUS Server?

A. Scan thru %WinDir%WindowsUpdate.log for the following entries :

(ie. C:WindowsWindowsUpdate.log);

3. What is the file %WINDIR%SoftwareDistributionReportingEvents.log used for on WSUS clients?

A. It appears to be where the WSUS client records update activities and results.

To display the current status of the Automatic Updates status

1. Click Start Run and type “cmd” to launch the Command prompt
2. From the command prompt, type
C:>SC sdshow wuauser

How to, reset the permissions as follows from the command prompt


C:>SC sdset wuauserv

There are actually two registry keys that are used when specifying a WSUS server.
Both of these keys are located at:

HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdate.
This registry key holds a string value which should be entered as the :
WSUS server’s URL (example: http://servername).
!
All command line options :

/DetectNow
/ReportNow
/RunHandlerComServer
/RunStoreAsComServer
/ShowSettingsDialog
/ResetAuthorization
/ResetEulas
/ShowWU
/ShowWindowsUpdate
/SelfUpdateManaged
/SelfUpdateUnmanaged
/UpdateNow
/ShowWUAutoScan
/ShowFeaturedUpdates
/ShowOptions
/ShowFeaturedOptInDialog
/DemoUI
!

To reset the Automatic Update client Open a command window :

Type wuauclt.exe /resetauthorization /detectnow

Wait 10 minutes for the detection cycle to finish.

To troubleshoot the Automatic Update client Open a command window :
Type: reg query HKLMSOFTWAREPoliciesMicrosoftWindowsWindowsUpdate

You should see output like the following if the client has been configured to get its updates from
a WSUS server:

HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdate
WUServer    REG_SZ  http://WSUSServerName
WUStatusServer      REG_SZ  http://WSUSServerName
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU


This works well. Save to a .cmd or batch file and run.

net stop wuauserv
REG DELETE “HKLMSoftwareMicrosoftWindowsCurrentVersionWindowsUpdate
Auto Update” /v LastWaitTimeout /f
REG DELETE “HKLMSoftwareMicrosoftWindowsCurrentVersionWindowsUpdate
Auto Update” /v DetectionStartTime /f
Reg Delete “HKLMSoftwareMicrosoftWindowsCurrentVersionWindowsUpdate
Auto Update” /v NextDetectionTime /f
net start wuauserv
wuauclt /detectnow

Report Now Steps :

wuauclt /a /detectnow
and then
wuauclt /r
for an update to occur

Telnet to SMTP

telnet ibmr.btconnect.com 25
helo google.com
mail from:ldjones48@hotmail.com
rcpt to:asalman@waveworks.co.uk
!
!
Type the following command to tell the SMTP server that you are ready to send data:
DATA

Type the following command to add a subject line:
Subject: test message

Type the following command to add message body text:
This is a test message you will not see a response from this command.

Type a period (.) at the next blank line, and then press ENTER. You receive the following response:

250 OK
Close the connection by typing the following command:
QUIT