You are not logged in.
Pages: 1
hello,
I decided to secure my Internet access with PPTP (VPN) access. I successfuly configured archlinux to act like pptp server, but I facet another problem. Right now every connected person receive random IP from pool configured in pptp configuration file.
But, I would like to have IP assigned to user ex.
user1 - always receive 192.168.10.1
user2 - always receive 192.168.10.2
userN - always receive 192.168.10.N
(no matter from what machine they connect, If user1 is logged in then he should receive 192.168.10.1 IP).
Right not I do not use radius for auth.
Can anybody help me ?
Offline
The forth column in /etc/ppp/chap-secrets lets you assign a static IP address per user. Replace the '*' with the IP you want that user to have.
user1 * User1Passwd 192.168.10.1
user2 * User2Passwd 192.168.10.2
Are you familiar with our Forum Rules, and How To Ask Questions The Smart Way?
BlueHackers // fscanary // resticctl
Offline
preface: I don't use pptp, and have very little experience with it. I end up preferring openvpn, or ipsec if business requirements dictate it.
That said, I don't think pptp supports persistant static allocations without the use of radius (radis Framed-IP-Address). Maybe someone more familiar with pptp will know if that is truly the case.
edit: fukawi2 for the win!
Last edited by cactus (2011-02-19 23:11:23)
"Be conservative in what you send; be liberal in what you accept." -- Postel's Law
"tacos" -- Cactus' Law
"t̥͍͎̪̪͗a̴̻̩͈͚ͨc̠o̩̙͈ͫͅs͙͎̙͊ ͔͇̫̜t͎̳̀a̜̞̗ͩc̗͍͚o̲̯̿s̖̣̤̙͌ ̖̜̈ț̰̫͓ạ̪͖̳c̲͎͕̰̯̃̈o͉ͅs̪ͪ ̜̻̖̜͕" -- -̖͚̫̙̓-̺̠͇ͤ̃ ̜̪̜ͯZ͔̗̭̞ͪA̝͈̙͖̩L͉̠̺͓G̙̞̦͖O̳̗͍
Offline
Maybe someone more familiar with pptp will know if that is truly the case.
We used to provide PPTP connections on our devices to many of our clients at my old work because OpenVPN and IPSec were too hard (ie, Windows doesn't have a built-in client).... Of course they still wanted specific firewall rules per-user so we had to give them static IP's too.
edit: fukawi2 for the win!
s/fukawi2/tacos/
Are you familiar with our Forum Rules, and How To Ask Questions The Smart Way?
BlueHackers // fscanary // resticctl
Offline
Thanks for replies.
I went with pptp because of native support in windows.
I wanted to connect from windows machine without additional software (other than provided by Microsoft).
I read that in chap-secrets I define ip from which user might connect not the one that user receive but I will give it a try.
Thanks to your replay I also now consider L2TP/IPSec with openSWAN as server (since windows xp/vista/7 supports this type of protocol).
Offline
Pages: 1