billing# cat /usr/local/etc/mpd5//mpd.conf
startup:
# enable TCP-Wrapper (hosts_access(5)) to block unfriendly clients
set global enable tcp-wrapper
# configure the console
set console self 127.0.0.1 5005
set user admin mpdpassword admin
set console open
#WEB managment
set web self 0.0.0.0 5006
set web open
#Netflow options
set netflow peer 127.0.0.1 9996
set netflow self 127.0.0.1 9990
set netflow timeouts 15 15
set netflow hook 9000
set link enable report-mac
#set netflow node netflow
log -echo -radius -rep
default:
load pppoe_client
load pptp_server
pppoe_client:
create bundle static B1
set iface route default
set ipcp ranges 0.0.0.0/0 0.0.0.0/0
create link static L1 pppoe
set link action bundle B1
set auth authname
login@dsl.ukrtel.net
set auth password password
set link max-redial 0
set link mtu 1492
set link keep-alive 10 60
#указываем свой сетевой интерфейс который смотрит в интернет у меня - nfe0
set pppoe iface nfe0
set pppoe service ""
open
pptp_server:
# set ippool add pool1 10.128.10.1 10.128.10.255
# Create clonable bundle template named B
create bundle template B
set iface enable proxy-arp
set iface idle 1800
set iface enable tcpmssfix
set iface up-script "/usr/abills/libexec/linkupdown mpd up"
set iface down-script "/usr/abills/libexec/linkupdown mpd down"
set ipcp yes vjcomp
# Specify IP address pool for dynamic assigment.
# set ipcp ranges 192.168.100.1/32 ippool pool1
set ipcp dns 213.179.249.131
# The five lines below enable Microsoft Point-to-Point encryption
# (MPPE) using the ng_mppc(8) netgraph node type.
set bundle enable compression
set ccp yes mppc
# set mppc yes e40
# set mppc yes e128
set mppc yes stateless
# Create clonable link template named L
create link template L pptp
# Set bundle template to use
set link action bundle B
# set link enable peer-as-calling
# set link enable report-mac
# Multilink adds some overhead, but gives full 1500 MTU.
set link enable multilink
set link yes acfcomp protocomp
set link no pap chap
set link enable chap
set link keep-alive 10 60
# We reducing link mtu to avoid GRE packet fragmentation
set link mtu 1460
# Configure PPTP
set pptp self 10.128.0.1
# Allow to accept calls
set link enable incoming
load server_common
load radius
server_common:
set link no pap eap
set link yes chap-md5
set link keep-alive 20 60
set link enable incoming
set link no acfcomp protocomp
load radius
radius:
set radius server 127.0.0.1 radsecret 1812 1813
set radius config /etc/radius.conf
set radius retries 3
set radius timeout 10
set auth acct-update 60
set auth enable radius-auth
set auth enable radius-acct
set auth disable internal
--------------------------------------------------------------------------------------------------