0002253Endian FirewallFirewall (iptables)public2009-10-08 13:342010-09-23 15:30
0002253: Firewall not passing GRE packets
I have two rules set up - one to pass tcp 1723 and another to pass Protocol 47 GRE to a single server running RRAS. Endian is not allowing GRE packets through to the server. I have confirmed this with the MS utilities pptpsrv and pptpclnt. The test makes a connection over 1723 but cannot get any packets to pass with GRE.

ANY suggestions would be greatly appreciated. I don't want to re-do the fireall with IPcop or Smoothwall at this point but we need PPTP VPN availability.

Am I missing something?
is t his a port forward or are you connecting from green to a pptp server in red?
Sorry - this is a port forward from red to green.
I also can confirm this problem on two seperate EFW2.2 firewalls.
I have the same two rules setup on EFW 2.2. To port forward from internet (red) to lan (green) for a pptp server on green, TCP 1723 and GRE and am unable to authenticate/connect due to GRE packets not passing to server via EFW firewall.
can anyone confirm this issue also for 2.3?
I can. After my 2.2 experience I went to 2.3 which did work for a while (a day) but has since stopped.

Interestingly, I use 2.2 on my personal home network and the VPN works fine so I'm not sure what the deal is here. I'm going to mount an ISA server as a test to make sure it's not provider related.
modem/router related is more likely than provider related IMHO
How are configured the two uplinks? In bridge mode?
Are the two modems/routers identical?
The uplinks are default - I haven't changed anything there since install. How do I check what mode they are in?

The two modems/routers are not identical but I know that both ISP services are wide open to each firewall.
I thought I had it figured out by adding the GRE rule to the "System Access" section in Firewall. It worked for about 12 hours and then stopped working.