Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CHR57
New Contributor III

PPTP want get out

I can't connect (Windows 10) PPTP from inside to out.

I have allowed all traffic from inside to outside.

 

I have checked that the Session Helper for PPTP is there.

 

The PPTP works as I have tried it with another fw.

 

Running v6.2.3

CR
CR
5 REPLIES 5
CHR57
New Contributor III

I have upgraded to 6.2.4 and I have made a factory reset, same problem.

The PPTP in windows gives me error code 829.

 

How do I debug the PPTP connection in the Fortigate?

CR
CR
CHR57
New Contributor III

I get these debug flow results; 

 

# diag debug flow filter saddr 192.168.100.103 # diag debug flow filter port 1723

 

2020-07-01 12:02:23 id=20085 trace_id=8 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag , seq 534983498, ack 0, win 64240" 2020-07-01 12:02:23 id=20085 trace_id=8 func=init_ip_session_common line=5788 msg="allocate a new session-0000ae19" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_dnat_check line=4951 msg="in-[lan], out-[]"[/size] 2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_dnat_check line=4964 msg="result: skb_flags-02000000, vid-0, ret-no-match, act-accept, flag-00000000" 2020-07-01 12:02:23 id=20085 trace_id=8 func=vf_ip_route_input_common line=2595 msg="find a route: flag=04000000 gw-100.127.114.1 via wan" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_fwd_check line=731 msg="in-[lan], out-[wan], skb_flags-02000000, vid-0, app_id: 0, url_cat_id: 0"[/size] 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_tree_check line=554 msg="gnum-100004, use addr/intf hash, len=2" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-100004 policy-1, ret-matched, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_user_identity_check line=1709 msg="ret-matched" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check line=2149 msg="gnum-4e20, check-7f023e64" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=1901 msg="checked gnum-4e20 policy-6, ret-no-match, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check line=2168 msg="gnum-4e20 check result: ret-no-match, act-accept, flag-00000000, flag2-00000000" 2020-07-01 12:02:23 id=20085 trace_id=8 func=get_new_addr line=1146 msg="find SNAT: IP-100.137.134.153(from IPPOOL), port-56350" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__iprope_check_one_policy line=2120 msg="policy-1 is matched, act-accept" 2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_fwd_auth_check line=786 msg="after iprope_captive_check(): is_captive-0, ret-matched, act-accept, idx-1" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=8 func=iprope_reverse_dnat_check line=1204 msg="in-[lan], out-[wan], skb_flags-02000000, vid-0"[/size] 2020-07-01 12:02:23 id=20085 trace_id=8 func=fw_forward_handler line=771 msg="Allowed by Policy-1: SNAT" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=8 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=9 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983499, ack 584345674, win 513"[/size] 2020-07-01 12:02:23 id=20085 trace_id=9 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=9 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=9 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=10 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983499, ack 584345674, win 513"[/size] 2020-07-01 12:02:23 id=20085 trace_id=10 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=10 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=10 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=11 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983655, ack 584345830, win 512"[/size] 2020-07-01 12:02:23 id=20085 trace_id=11 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=11 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=11 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:23 id=20085 trace_id=12 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983823, ack 584345862, win 512"[/size] 2020-07-01 12:02:23 id=20085 trace_id=12 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:23 id=20085 trace_id=12 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:23 id=20085 trace_id=12 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:53 id=20085 trace_id=13 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [.], seq 534983847, ack 584345863, win 512"[/size] 2020-07-01 12:02:53 id=20085 trace_id=13 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:53 id=20085 trace_id=13 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:53 id=20085 trace_id=13 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)" [size="1"]2020-07-01 12:02:53 id=20085 trace_id=14 func=print_pkt_detail line=5618 msg="vd-root:0 received a packet(proto=6, 192.168.100.103:56350->94.254.51.237:1723) from lan. flag [F.], seq 534983847, ack 584345863, win 512"[/size] 2020-07-01 12:02:53 id=20085 trace_id=14 func=resolve_ip_tuple_fast line=5698 msg="Find an existing session, id-0000ae19, original direction" 2020-07-01 12:02:53 id=20085 trace_id=14 func=__ip_session_run_tuple line=3396 msg="SNAT 192.168.100.103->100.137.134.153:56350" 2020-07-01 12:02:53 id=20085 trace_id=14 func=__ip_session_run_tuple line=3447 msg="run helper-pptp(dir=original)"

CR
CR
MIN2325
New Contributor

Hey!

please how can i configure pptp on the fortigate firewall?

I noticed you have done that already. I have Mikrotik routers throughout my network and runs pptp VPN well but the firewall does not allow VPN pass

can you help me out?

 

sw2090
Honored Contributor

hm Fortinet KB suggestes to do L2TP with WIndows 10. THere is a KB Article on that: https://kb.fortinet.com/kb/documentLink.do?externalID=FD44157

 

I also found this: https://docs.fortinet.com/document/fortigate/6.0.0/handbook/232068/pptp-and-l2tp

 

maybe it helps.

 

Cannot say anything about pptp as I dont use it. I tried l2tp in win10 with a FGT once and it worked. 

For dial in VPN at homeoffice I prefer using Shrewsoft or Forticlient and IPSec Tunnels.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
CHR57
New Contributor III

Looked at your last URL.

 

They mention that you should do a VIP and a policy for the VIP to get a PPTP passthrough.

I have hard to believe that and if multiple IPs on the lan need to get out by PPTP, what should the VIP then point to on the lan?

 

The PPTP passthrough used to work (same external VPN PPTP server) on the FortiGate and then stopped working by any reason (firmware upgrade?). Note that PPTP works when I from the same computer access it without the Fortigate.

CR
CR
Labels
Top Kudoed Authors