Estava tentando acertar meu firewall para permitir o acesso a VPN no windows Server, achei este código salvador:
http://under-linux.org/f96/vpn-pptp-firewall-iptables-89330/
SERVER=192.168.0.1 IF_WAN=eth1 iptables -A INPUT -p tcp --dport 1723 -j ACCEPT iptables -A INPUT -p 47 -j ACCEPT iptables -A FORWARD -p TCP --dport 1723 -j ACCEPT iptables -A FORWARD -p 47 -j ACCEPT iptables -t nat -A PREROUTING -i $IF_WAN -p tcp --dport 1723 -j DNAT --to 192.168.0.150 $IPT -t nat -A PREROUTING -i $IF_WAN -p 47 -j DNAT --to $SERVER



