Groups | Search | Server Info | Keyboard shortcuts | Login | Register


Groups > comp.protocols.ppp > #129

Re: "CHAP authentication succeeded" followed by "Authentication failed"

From Eric Pozharski <whynot@pozharski.name>
Newsgroups comp.protocols.ppp
Subject Re: "CHAP authentication succeeded" followed by "Authentication failed"
Date 2022-04-27 11:56 +0000
Organization A noiseless patient Spider
Message-ID <slrnt6ibqu.fat.whynot@orphan.zombinet> (permalink)
References <t2g132$qns$1@bidski.eternal-september.org> <slrnt515nq.sh9.whynot@orphan.zombinet> <t2uiqt$orq$1@bidski.eternal-september.org> <slrnt5d8b7.io0.whynot@orphan.zombinet> <t478hb$c9v$1@bidski.eternal-september.org>

Show all headers | View raw


with <t478hb$c9v$1@bidski.eternal-september.org> Bidski wrote:
> On 13/4/22 20:09, Eric Pozharski wrote:

>> Meanwhile, I suggest dropping all 'require-*' and 'refuse-*' lines
>> from 'options.l2tpd.client', keeping 'ipcp-accept-*';  moving
>> 'chap-secrets' to '/etc/xl2tpd/l2tp-secrets' (I insist, where it
>> belongs);  adjusting 'auth file' line of 'xl2tpd.conf' accordingly;
>> and try xl2tpd again.  Look, it's not working now, it might not work
>> differently.
> I tried moving the contents of 'chap-secrets' into 'l2tp-secrets',
> however, ppp then complains that "No auth is possible", if I also
> remove the line "name MY_NAME" from the ppp options file then no
> connection is established at all (literally nothing happens with no
> output from pppd or xl2tpd). With "name MY_NAME" and the corresponding
> secret in 'chap-secrets' ppp will establish and authenticate me to the
> peer and with the same secret in 'l2tp-secrets' xl2tpd also
> authenticates me to the peer and I have an active connection.

My guess would be that you didn't get rid of 'require-*' and 'refuse-*'
lines of 'options.l2tpd.client'.  I speculate (without logs of pppd) you
are back to square one (maybe square one-and-a-quarter).

> Adding a route to direct all VPN traffic through the ppp0 interface
> allows me to ping IP addresses that I know are on the server side of
> the connection, and there is a webserver that I can access through my
> browser, so that all seems good.

I'm not xl2tpd user but my understanding is you're not supposed to touch
*underlying* ppp-link.  I speculate (without xl2tpd logs) you're
breaking it even more.

> Unfortunately, I am unable to ssh into machines that I know I should
> be able to ssh into. I don't currently have the logs available to me
> at the moment, but I think ssh is waiting for a response from the
> remote server and is not getting it. Do you know if there is anything
> specific I need to do to allow ssh to work over the VPN connection?

With breakage that enormous any behaviour is possible.  Though the
breakage isnt FUBAR yet.

-- 
Torvalds' goal for Linux is very simple: World Domination
Stallman's goal for GNU is even simpler: Freedom

Back to comp.protocols.ppp | Previous | NextPrevious in thread | Find similar


Thread

"CHAP authentication succeeded" followed by "Authentication failed" Bidski <bidskii@gmail.com> - 2022-04-05 10:04 +1000
  Re: "CHAP authentication succeeded" followed by "Authentication failed" Eric Pozharski <whynot@pozharski.name> - 2022-04-08 20:11 +0000
    Re: "CHAP authentication succeeded" followed by "Authentication failed" Bidski <bidskii@gmail.com> - 2022-04-10 22:33 +1000
      Re: "CHAP authentication succeeded" followed by "Authentication failed" Eric Pozharski <whynot@pozharski.name> - 2022-04-13 10:09 +0000
        Re: "CHAP authentication succeeded" followed by "Authentication failed" Bidski <bidskii@gmail.com> - 2022-04-26 08:49 +1000
          Re: "CHAP authentication succeeded" followed by "Authentication failed" Eric Pozharski <whynot@pozharski.name> - 2022-04-27 11:56 +0000

csiph-web