Temat: OpenWRT BB i serwer PPTP
Witam posiadam TP-LINK TL-WR740N v 4.23 z OpenWRT BB by obsy z LUci
Chcę postawić na nim serwer PPTP
Na routerze mam internet przez tryb AP + AP Client
Łączę się z moją główną siecią po wifi ( Neostrada Router Sagemcom Fast 2704 ) i rozsyłam dalej po innym ssid i haśle
Adres Sagemcoma to 192.168.1.1
Adres TP-LINKA to 192.168.3.1
Adres jaki TP-LINK dostaje od Sagemcoma to 192.168.1.5
Na Sagemie przekierowany port 1723 dla 192.168.1.5![]()
Jak skonfigurować ten serwer PPTP
Plik /etc/pptpd.conf wygląda tak :
#debug
option /etc/ppp/options.pptpd
speed 115200
stimeout 10
#localip & remoteip are not needed, ip management is done by pppd
localip 192.168.3.1
remoteip 192.168.3.81-99
Plik /etc/ppp/options.pptpd tak :
#debug
#logfile /tmp/pptp-server.log
auth
name "pptp-server"
lcp-echo-failure 3
lcp-echo-interval 60
default-asyncmap
mtu 1482
mru 1482
nobsdcomp
nodeflate
proxyarp
#nomppc
mppe required,no40,no56,stateless
require-mschap-v2
refuse-chap
refuse-mschap
refuse-eap
refuse-pap
ms-dns 192.168.3.1
#plugin radius.so
#radius-config-file /etc/radius.conf
A plik /etc/ppp/chap-secrets tak :
Norbert * mojehaslo *
Plik /etc/config/firewall tak :
config defaults
option syn_flood '1'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'REJECT'
config zone
option name 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
option network 'lan'
config zone
option name 'wan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1'
option mtu_fix '1'
option network 'wan wan6 wwan'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option src_ip 'fe80::/10'
option src_port '547'
option dest_ip 'fe80::/10'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'PPTP'
option src 'wan'
option dest_port '1723'
option proto 'tcp'
option target 'ACCEPT'
config include
option path '/etc/firewall.user'
config redirect
option target 'DNAT'
option src 'wan'
option dest 'lan'
option proto 'tcp udp'
option src_dport '1723'
option dest_ip '192.168.3.1'
option dest_port '1723'
option name 'PPTP'
config redirect
option enabled '1'
option target 'SNAT'
option src 'lan'
option dest 'wan'
option src_dip '192.168.3.1'
option src_dport '1723'
option name 'PPTP'
option proto 'tcp'
option src_ip '192.168.3.1'
option src_port '1723'
option dest_ip '192.168.3.1'
option dest_port '1723'
Jak to skonfigurować aby serwer działał ?