|
|
|
@ -1,7 +1,7 @@
|
|
|
|
|
diff -Naur xl2tpd-1.3.1-orig/examples/chapsecrets.sample xl2tpd-1.3.1/examples/chapsecrets.sample
|
|
|
|
|
--- xl2tpd-1.3.1-orig/examples/chapsecrets.sample 2011-10-06 15:22:05.000000000 -0400
|
|
|
|
|
+++ xl2tpd-1.3.1/examples/chapsecrets.sample 2012-06-12 12:08:26.850851970 -0400
|
|
|
|
|
@@ -1,7 +1,9 @@
|
|
|
|
|
@@ -1,7 +1,10 @@
|
|
|
|
|
-# Secrets for authentication using CHAP
|
|
|
|
|
-# client server secret IP addresses
|
|
|
|
|
-jacco * "mysecret" 192.168.1.128/25
|
|
|
|
@ -10,6 +10,7 @@ diff -Naur xl2tpd-1.3.1-orig/examples/chapsecrets.sample xl2tpd-1.3.1/examples/c
|
|
|
|
|
-* sam "rumpelstiltskin" 192.168.1.5
|
|
|
|
|
-
|
|
|
|
|
+# Secrets for authentication on server using CHAP
|
|
|
|
|
+# See /etc/ppp/options.xl2tpd on how to use Windows authentication
|
|
|
|
|
+# client server secret IP addresses
|
|
|
|
|
+jacco * "mysecret" 192.168.1.128/25 # Dynamic IP
|
|
|
|
|
+sam * "rumpelstiltskin" 192.168.1.5 # Static IP
|
|
|
|
@ -61,3 +62,33 @@ diff -Naur xl2tpd-1.3.1-orig/examples/xl2tpd.conf xl2tpd-1.3.1/examples/xl2tpd.c
|
|
|
|
|
refuse pap = yes
|
|
|
|
|
require authentication = yes
|
|
|
|
|
name = LinuxVPNserver
|
|
|
|
|
diff -aur xl2tpd-1.3.1-orig/examples/ppp-options.xl2tpd xl2tpd-1.3.1/examples/ppp-options.xl2tpd
|
|
|
|
|
--- xl2tpd-1.3.1-orig/examples/ppp-options.xl2tpd 2011-10-06 15:22:05.000000000 -0400
|
|
|
|
|
+++ xl2tpd-1.3.1/examples/ppp-options.xl2tpd 2012-07-19 10:54:13.810503823 -0400
|
|
|
|
|
@@ -1,9 +1,10 @@
|
|
|
|
|
ipcp-accept-local
|
|
|
|
|
ipcp-accept-remote
|
|
|
|
|
-ms-dns 192.168.1.1
|
|
|
|
|
-ms-dns 192.168.1.3
|
|
|
|
|
-ms-wins 192.168.1.2
|
|
|
|
|
-ms-wins 192.168.1.4
|
|
|
|
|
+ms-dns 8.8.8.8
|
|
|
|
|
+# ms-dns 192.168.1.1
|
|
|
|
|
+# ms-dns 192.168.1.3
|
|
|
|
|
+# ms-wins 192.168.1.2
|
|
|
|
|
+# ms-wins 192.168.1.4
|
|
|
|
|
noccp
|
|
|
|
|
auth
|
|
|
|
|
crtscts
|
|
|
|
|
@@ -15,3 +16,11 @@
|
|
|
|
|
lock
|
|
|
|
|
proxyarp
|
|
|
|
|
connect-delay 5000
|
|
|
|
|
+# To allow authentication against a Windows domain EXAMPLE, and require the
|
|
|
|
|
+# user to be in a group "VPN Users". Requires the samba-winbind package
|
|
|
|
|
+# require-mschap-v2
|
|
|
|
|
+# plugin winbind.so
|
|
|
|
|
+# ntlm_auth-helper '/usr/bin/ntlm_auth --helper-protocol=ntlm-server-1 --require-membership-of="EXAMPLE\\VPN Users"'
|
|
|
|
|
+# You need to join the domain on the server, for example using samba:
|
|
|
|
|
+# http://rootmanager.com/ubuntu-ipsec-l2tp-windows-domain-auth/setting-up-openswan-xl2tpd-with-native-windows-clients-lucid.html
|
|
|
|
|
+
|
|
|
|
|