l2tpns does not appear to route packets from/to ranges not within that which is allocated to the tunnels themselves. Consider for example [E:192.168.0.0/24]--[LAC:10.0.0.2]---[LNS:10.0.0.1]--[E:192.168.1.0/24] It seems l2tpns will only route traffic over the tun interface if it is natted (the source address is either the tunnel or the LNS IP) making it fairly useless for most uses of L2TP. l2tp does not provide any useful debugging from my side, only that when I do something like 'traceroute -s 192.168.0.1 10.0.0.1' the packets hit the tun0 interface from tcpdump, but tcpdump on the other end does not see anything. l2tpd claims to do gratuitous arp, but I don't see any such thing happening and the documentation fails to explain how it treats routing information. Debian Release: 4.0 APT prefers stable APT policy: (500, 'stable') Architecture: i386 (i686) Shell: /bin/sh linked to /bin/bash Kernel: Linux 2.6.18-6-686 Locale: LANG=en_ZA.UTF-8, LC_CTYPE=en_ZA.UTF-8 (charmap=UTF-8) Versions of packages l2tpns depends on: ii libc6 2.3.6.ds1-13etch5 GNU C Library: Shared libraries ii libcli1 1.8.6-1 emulates a cisco style telnet comm l2tpns recommends no packages.
l2tpns will only route traffic over the tun interface if it knows about the appropriate IPs. How do you expect it to know which end point to route to otherwise? You don't supply any details of your RADIUS config but at a guess you haven't got a Framed-Route entry for the network you want to route to the username in question? I have used l2tpns with non NATed routed subnets in the past without problems. Have you tried altering the debug level (set debug <n>)? J.
Jonathan McDowell wrote: Considering I have an interface with a /24 set on it, and IP's directly connected to that, I assumed adding a route with the last hop IP as a gateway would work. Much like it does on any other. Doesn't l2tpns receive this routing information already? I don't have a Frame-Route, no. From RADIUS documentation that attribute suggests it is a route to pass along to the LAC. I'm guessing l2tpns does not document its treatment of that attribute, or I'm blind. I will test it though, so thank you. Yes, it didn't seem to provide any detail
Colin Alston wrote: Apparently I am blind, and stupid. I do need a Framed-Route attribute. The documentation still sucks :( But I'll try deal with that.
severity wishlist retitle documentation could do with much improvement thanks Glad that sorted for you. Agreed on the documentation front, so I'll keep this bug around as a general reminder about that. J.
Dear submitter, as the package l2tpns has just been removed from the Debian archive unstable we hereby close the associated bug reports. We are sorry that we couldn't deal with your issue properly. For details on the removal, please see https://bugs.debian.org/929610 The version of this package that was in Debian prior to this removal can still be found using http://snapshot.debian.org/. This message was generated automatically; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org. Debian distribution maintenance software pp. Scott Kitterman (the ftpmaster behind the curtain)