# yum install -y ppp iptables
# rpm -Uvh http://poptop.sourceforge.net/yum/stable/rhel6/pptp-release-current.noarch.rpm
# yum install pptpd
mv /etc/ppp/options.pptpd /etc/ppp/options.pptpd.bak
vi /etc/ppp/options.pptpd
mv /etc/ppp/chap-secrets /etc/ppp/chap-secrets.bak
vi /etc/ppp/chap-secrets
mv /etc/pptpd.conf /etc/pptpd.conf.bak
vi /etc/pptpd.conf
vi /etc/sysctl.conf
修改以下內容:
net.ipv4.ip_forward = 1
保存、退出後執行:
/sbin/sysctl -p
#======================>>> Forward table <<<========================
# Motify MTU
iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
#======================>>> nat table <<<========================
# flush nat table
iptables -t nat -F
# setup policy
iptables -t nat -P PREROUTING ACCEPT
iptables -t nat -P OUTPUT ACCEPT
iptables -t nat -P POSTROUTING ACCEPT
# Masq internal hosts
iptables -A POSTROUTING -t nat -s 192.168.10.0/255.255.255.0 -j MASQUERADE
這樣應該就完成了,接下來就可以正式測試VPN的連線。
備註:防火牆設定
PPTP的運作需要使用 TCP Port 1723 ...所以測試時需要留意 1723 port 有沒有開放囉~~
歡迎光臨 ADJ網路實驗室 (http://dz.adj.idv.tw/) | Powered by Discuz! 6.0.0 |