network-manager-pptp defaults are rarely workable / useful on Jaunty.

Bug #352600 reported by Carl Farrington
14
This bug affects 1 person
Affects Status Importance Assigned to Milestone
network-manager-pptp (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: network-manager-pptp

I'm using Jaunty.
I wonder if the default options for VPN connections in network-manager-pptp might be set to something that's more likely to work out of the box than that which is currently set.

PPTP is perhaps most commonly used in the Windows world, and for other simple-to-configure road-warrior type setups, e.g. Draytek routers and what not.

The defaults out of the box on Jaunty do not appear to work with a typical Microsoft Routing and Remote Access Sever (RRAS) setup.

It seems that the following needs to be changed before a connection can be made:

EAP needs to be de-selected as an authentication method, else we see something like this from pppd:
EAP: unknown authentication type 13; Naking
LCP terminated by peer (+M-`^BM-4^@<M-Mt^@^@^BM-3)

MPPE needs to be enabled, else we see something like this:
Mar 31 19:33:31 mediaxp kernel: [ 7008.521609] PPP BSD Compression module registered
Mar 31 19:33:31 mediaxp kernel: [ 7008.548198] PPP Deflate Compression module registered
Mar 31 19:33:31 mediaxp pppd[9687]: LCP terminated by peer (4M-vXM-2^@<M-Mt^@^@^BM-f)
Mar 31 19:33:34 mediaxp pppd[9687]: Connection terminated.

It seems that with MPPE enabled, we no longer get the BSD Compression or PPP Deflate messages from the kernel, but instead we get "MPPE 128-bit stateless compression enabled", and the connection works as it should, bar the routing issues which are sorted by manually entering the network/mask in the IPv4 settings tab - I beleive this is a known issue.

So I wonder if it would make sense to set these options as default.

I can do some testing against Draytek routers (2600, 2800 & 3100) if this would be of any use.

As an aside, I seem totally unable to get a connection to any of my customer's Draytek PPTP routers, or a pfSense box I have at a site.

description: updated
Revision history for this message
Carl Farrington (carl-css-networks) wrote :

Having experimented a bit more, I am able to connect to a Draytek Vigor 2950. The Draytek connection appears to work regardless of the options above, i.e. with or without the changes to settings that are required by the MS PPTP server.

Revision history for this message
Carl Farrington (carl-css-networks) wrote :

Apologies for continually adding to this report, but I have additional information.

Here's a summary:

Microsoft RRAS PPTP Servers don't work with EAP ticked in nm-pptp, they also require MPPE to be ticked.
Draytek Vigor routers don't care and just work, the Vigor 2950 I just tested appears to anyway.
pfSense (FreeBSD berkely packet-filter or something based Monowall-fork thing) doesn't work unless MPPE is ticked.

So it definately seems like some defaults of : "EAP: No; MPPE: Yes" would work good out of the box.

Revision history for this message
Nils-Werner Claesson (nwclaesson) wrote :

Related to Bug #150665?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.