Skip to main content
CHR57
Explorer II
April 26, 2020
Question

PPTP want get out

  • April 26, 2020
  • 2 replies
  • 5044 views

I can't connect (Windows 10) PPTP from inside to out.

I have allowed all traffic from inside to outside.

 

I have checked that the Session Helper for PPTP is there.

 

The PPTP works as I have tried it with another fw.

 

Running v6.2.3

2 replies

CHR57
CHR57Author
Explorer II
July 1, 2020

I have upgraded to 6.2.4 and I have made a factory reset, same problem.

The PPTP in windows gives me error code 829.

 

How do I debug the PPTP connection in the Fortigate?

CHR57
CHR57Author
Explorer II
July 1, 2020

I get these debug flow results; 

 

# diag debug flow filter saddr 192.168.100.103 # diag debug flow filter port 1723

 

2020-07-01 12:02:23 id=20085 trace_id=8 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag , seq 534983498, ack 0, win 64240" 2020-07-01 12:02:23 id=20085 trace_id=8 func=init_ip_session_common line=5788 msg="allocate a new session-0000ae19" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_dnat_check line=4951 msg="in-[lan], out-[]"[/size] 2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_dnat_check line=4964 msg="result: skb_flags-02000000, vid-0, ret-no-match, act-accept, flag-00000000" 2020-07-01 12:02:23 id=20085 trace_id=8 func=vf_ip_route_input_common line=2595 msg="find a route: flag=04000000 gw-100.127.114.1 via wan" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_fwd_check line=731 msg="in-[lan], out-[wan], skb_flags-02000000, vid-0, app_id: 0, url_cat_id: 0"[/size] 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_tree_check line=554 msg="gnum-100004, use addr/intf hash, len=2" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-100004 policy-1, ret-matched, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_user_identity_check line=1709 msg="ret-matched" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check line=2149 msg="gnum-4e20, check-7f023e64" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check line=2168 msg="gnum-4e20 check result: ret-no-match, act-accept, flag-00000000, flag2-00000000" 2020-07-01 12:02:23 id=20085 trace_id=8 func=get_new_addr line=1146 msg="find SNAT: IP-100.137.134.153(from IPPOOL), port-56350" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=2120 msg="policy-1 is matched, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_fwd_auth_check line=786 msg="after iprope_captive_check(): is_captive-0, ret-matched, act-accept, idx-1" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_reverse_dnat_check line=1204 msg="in-[lan], out-[wan], skb_flags-02000000, vid-0"[/size] 2020-07-01 12:02:23 id=20085 trace_id=8 func=fw_forward_handler line=771 msg="Allowed by Policy-1: SNAT" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=9 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983499, ack 584345674, win 513"[/size] 2020-07-01 12:02:23 id=20085 trace_id=9 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=9 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=9 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=10 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983499, ack 584345674, win 513"[/size] 2020-07-01 12:02:23 id=20085 trace_id=10 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=10 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=10 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=11 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983655, ack 584345830, win 512"[/size] 2020-07-01 12:02:23 id=20085 trace_id=11 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=11 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=11 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=12 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983823, ack 584345862, win 512"[/size] 2020-07-01 12:02:23 id=20085 trace_id=12 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=12 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=12 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:53 id=20085 trace_id=13 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983847, ack 584345863, win 512"[/size] 2020-07-01 12:02:53 id=20085 trace_id=13 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:53 id=20085 trace_id=13 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:53 id=20085 trace_id=13 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:53 id=20085 trace_id=14 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [F.], seq 534983847, ack 584345863, win 512"[/size] 2020-07-01 12:02:53 id=20085 trace_id=14 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:53 id=20085 trace_id=14 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:53 id=20085 trace_id=14 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)"

MIN2325
New Member
July 1, 2020

Hey!

please how can i configure pptp on the fortigate firewall?

I noticed you have done that already. I have Mikrotik routers throughout my network and runs pptp VPN well but the firewall does not allow VPN pass

can you help me out?

 

sw2090
SuperUser
SuperUser
July 2, 2020

hm Fortinet KB suggestes to do L2TP with WIndows 10. THere is a KB Article on that: https://kb.fortinet.com/kb/documentLink.do?externalID=FD44157

 

I also found this: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/232068/pptp-and-l2tp

 

maybe it helps.

 

Cannot say anything about pptp as I dont use it. I tried l2tp in win10 with a FGT once and it worked. 

For dial in VPN at homeoffice I prefer using Shrewsoft or Forticlient and IPSec Tunnels.