jhtwu / vigor2130

Automatically exported from code.google.com/p/vigor2130
0 stars 0 forks source link

Multi WAN and pptp passthrough tied to all WAN addresses #92

Open GoogleCodeExporter opened 9 years ago

GoogleCodeExporter commented 9 years ago
Firmware 1.5.2, 2130(plain)

Issue: using pptp pass-through, pptp(GRE) is tied to all WAN addresses(WAN IP 
Alias ( Multi-NAT )).

Desc. when you use an IP range like 123.4.5.1 - 123.4.5.10, pptp pass-through 
is enabled in order for port 1723 to get through, you also need a NAT firewall 
rule to allow full pptp traffic to reach the server.

However, when the pptp server is located on another WAN address (multi WAN) and 
the rule is changed to reflect the new WAN pptp address the pass-through 
setting will still list port 1723 to be open on all WAN addresses. (because the 
pass-through option only allows an internal address and is not bound to a WAN 
interface)

Assuming pptp pass-through is required for GRE.

My request is to allow pptp pass-through (GRE) to be assigned to a WAN 
interface. (VPN and Remote Access >> Remote Access Control, Enable PPTP VPN 
Pass-through (Server inside your LAN))

The issue is obvious since pptp traffic does not get passed on any other WAN 
address then the one using a rule for port 1723, but all WAN addresses show 
1723 to be open.

Original issue reported on code.google.com by i...@ecsystems.nl on 9 Jul 2012 at 8:38