我已经在 PfSense 21.05-RELEASE (amd64) 和 fedora 33 上配置了 L2TP VPN 作为客户端,一旦连接了 VPN,我就可以 ping 远程主机,但是一旦我绑定到 HTTP 流量 VPN 就会停止流量。
在 TCP 转储中可以看到传出流量,但在 HTTP 请求后没有传入流量返回似乎与打包程序重新组装有关
链输入(策略接受)
目标 prot opt 源目标
接受所有 - 任何地方任何地方状态相关,已建立
接受 icmp——随时随地
接受所有——任何地方的任何地方
接受 tcp -- 任何地方的任何地方都有新的 tcp dpt:ssh
REJECT all - 任何地方都拒绝 - 使用 icmp-host-prohibited
Chain FORWARD (policy ACCEPT) target prot opt source destination
REJECT all -- 任何地方任何地方都拒绝-with icmp-host-prohibited
Chain OUTPUT (policy ACCEPT) target prot opt source destination
2: ppp0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1400 qdisc fq_codel state UNKNOWN group default qlen 3
link/ppp
inet 10.200.200.0 peer 10.200.0.1/32 scope global ppp0
valid_lft forever preferred_lft forever
14:10:37.880312 IP fedora > b.resolvers.Level3.net:ICMP 回显请求,id 25,seq 1,长度 64
14:10:38.046771 IP b.resolvers.Level3.net > fedora:ICMP echo 回复,id 25,seq 1,长度 64
14:10:38.880819 IP fedora > b.resolvers.Level3.net:ICMP 回显请求,id 25,seq 2,长度 64
14:10:39.047254 IP b.resolvers.Level3.net > fedora:ICMP echo 回复,id 25,seq 2,长度 64
14:10:39.880860 IP fedora > b.resolvers.Level3.net:ICMP 回显请求,id 25,seq 3,长度 64
14:10:40.046325 IP b.resolvers.Level3.net > fedora:ICMP echo 回复,id 25,seq 3,长度 64
14:10:52.048093 IP xcal1.vodafone.co.uk.http > fedora.37900:标志 [.],ack 140,win 123,长度 0
14:10:52.050555 IP xcal1.vodafone.co.uk.http > fedora.37900: 标志 [.], seq 1:1361, ack 140, win 123, 长度 1360: HTTP: HTTP/1.1 200 OK
14:10:52.050575 IP fedora.37900 > xcal1.vodafone.co.uk.http:标志 [.],ack 1361,win 502,长度 0
14:10:52.050593 IP xcal1.vodafone.co.uk.http > fedora.37900:标志 [.],seq 1361:2721,ack 140,win 123,长度 1360:HTTP
14:10:52.050603 IP fedora.37900 > xcal1.vodafone.co.uk.http:标志 [.],ack 2721,win 496,长度 0
14:10:52.050605 IP xcal1.vodafone.co.uk.http > fedora.37900:标志 [.],seq 2721:4081,ack 140,win 123,长度 1360:HTTP
14:10:52.050608 IP fedora.37900 > xcal1.vodafone.co.uk.http: 标志 [.], ack 4081, win 489, 长度 0
14:10:52.051180 IP xcal1.vodafone.co.uk.http > fedora.37900:标志 [.],seq 4081:5441,ack 140,win 123,长度 1360:HTTP
14:10:52.051193 IP fedora.37900 > xcal1.vodafone.co.uk.http:标志 [.],ack 5441,win 481,长度 0
14:13:06.781830 IP fedora.38648 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 684941377, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:32.424321 IP fedora.38650 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3466381594, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:32.674485 IP fedora.38652 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3214804727, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:33.469787 IP fedora.38650 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3466381594, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:33.725967 IP fedora.38652 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3214804727, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:35.517903 IP fedora.38650 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3466381594, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:35.773924 IP fedora.38652 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3214804727, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:39.549856 IP fedora.38650 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3466381594, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:39.805863 IP fedora.38652 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3214804727, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:47.741806 IP fedora.38650 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3466381594, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:13:48.253781 IP fedora.38652 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3214804727, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:14:04.125969 IP fedora.38650 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3466381594, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:14:04.637813 IP fedora.38652 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3214804727, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:14:36.381831 IP fedora.38650 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3466381594, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0
14:14:36.893792 IP fedora.38652 > 239.237.117.34.bc.googleusercontent.com.https: Flags [S], seq 3214804727, win 65280, options [mss 1360,nop,nop,sackOK,nop,wscale 7],长度 0