Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gabesms
New Contributor

Unable to passthrough PPTP VPN to a external server [SOLVED]

Sirs

 

I'm starting with the fotigate and I am unable to configure the FortiGate to allow PPTP VPN connection from my internal network out to an external server. I setup a policy allowing traffic of the LAN interface, for the LAN IPs and WAN Interface, IP VPN; Service PPTP and GRE;

Enable NAT

 

(examples) IP WAN: 182.231.220.6 IP LAN: client 10.10.100.124 IP VPN SERVER 201.165.162.190 port1: LAN

Wan1: wan

When I test the connection I have the following in the debug LOG flow : titulo_fw1 # 2015-08-18 15:34:42 2015-08-18 15:34:42 id=13 trace_id=1971 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:42 id=13 trace_id=1971 func=init_ip_session_common line=4424 msg="allocate a new session-2e82d9d1" 2015-08-18 15:34:42 id=13 trace_id=1971 func=vf_ip4_route_input line=1603 msg="find a route: gw-182.231.220.1 via wan1" 2015-08-18 15:34:43 id=13 trace_id=1971 func=__iprope_tree_check line=534 msg="use addr/intf hash, len=13" 2015-08-18 15:34:43 id=13 trace_id=1972 func=__ip_session_run_tuple line=2519 msg="DNAT 182.231.220.6:65401->10.10.100.124:65401" 2015-08-18 15:34:43 id=13 trace_id=1972 func=vf_ip4_route_input line=1603 msg="find a route: gw-10.10.255.2 via port1" id=13 trace_id=1971 func=fw_forward_handler line=660 msg="Allowed by Policy-199: SNAT" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1972 func=ids_receive line=237 msg="send to ips" id=13 trace_id=1971 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1973 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1973 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" id=13 trace_id=1974 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1973 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1974 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1975 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, reply direction" 2015-08-18 15:34:43 id=13 trace_id=1974 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" 2015-08-18 15:34:43 id=13 trace_id=1975 func=__ip_session_run_tuple line=2519 msg="DNAT 182.231.220.6:65401->10.10.100.124:65401" 2015-08-18 15:34:43 id=13 trace_id=1974 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1975 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1978 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1976 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1976 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1978 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" id=13 trace_id=1976 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1976 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1977 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 201.165.162.190:1723->182.231.220.6:65401) from wan1." 2015-08-18 15:34:43 id=13 trace_id=1977 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, reply direction" 2015-08-18 15:34:43 id=13 trace_id=1977 func=__ip_session_run_tuple line=2519 msg="DNAT 182.231.220.6:65401->10.10.100.124:65401" 2015-08-18 15:34:43 id=13 trace_id=1977 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 id=13 trace_id=1978 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1979 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=6, 10.10.100.124:65401->201.165.162.190:1723) from port1." 2015-08-18 15:34:43 id=13 trace_id=1979 func=resolve_ip_tuple_fast line=4329 msg="Find an existing session, id-2e82d9d1, original direction" 2015-08-18 15:34:43 id=13 trace_id=1980 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=47, 10.10.100.124:0->201.165.162.190:2527) from port1." 2015-08-18 15:34:43 id=13 trace_id=1979 func=ids_receive line=237 msg="send to ips" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1980 func=init_ip_session_common line=4424 msg="allocate a new session-2e82da04" id=13 trace_id=1979 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:65401" 2015-08-18 15:34:43 id=13 trace_id=1980 func=__ip_session_run_tuple line=2505 msg="SNAT 10.10.100.124->182.231.220.6:0" id=13 trace_id=1980 func=vf_ip4_route_input line=1603 msg="find a route: gw-182.231.220.1 via wan1" 2015-08-18 15:34:43 id=13 trace_id=1981 func=resolve_ip_tuple_fast line=4295 msg="vd-root received a packet(proto=47, 201.165.162.190:0->182.231.220.6:41210) from wan1." 2015-08-18 15:34:43 id=13 trace_id=1980 func=__iprope_tree_check line=534 msg="use addr/intf hash, len=13" 2015-08-18 15:34:43 id=13 trace_id=1980 func=get_new_addr line=2398 msg="find SNAT: IP-182.231.220.6, port-0" 2015-08-18 15:34:43 id=13 trace_id=1980 func=fw_forward_handler line=660 msg="Allowed by Policy-199: SNAT" 2015-08-18 15:34:43 2015-08-18 15:34:43 id=13 trace_id=1980 func=ids_receive line=237 msg="send to ips" id=13 trace_id=1981 func=init_ip_session_common line=4424 msg="allocate a new session-2e82da05" 2015-08-18 15:34:43 id=13 trace_id=1981 func=fw_local_in_handler line=357 msg="iprope_in_check() check failed, drop" Any thing helps (and some tips to understand this log are welcome)

 

Thanks!

 

EDIT:

 

Cause some reason, the all the session helpers was removed.

I Run:

show system session-helper

And get nothing

So I Run:

config system session-helper
edit 1
        set name pptp
        set port 1723
        set protocol 6
    next
end

 

And works! Thanks!

0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors