<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PPTP with NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pptp-with-nat/m-p/502151#M1055644</link>
    <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;One of my costumers is connected to my Internet network (im an isp), the costumer is using dynamic nat, and on the other end, there is a PPTP server (on a hosted environment), the costumer complains that sometimes can´t connect throught the pptp tunnel, but i always see the TCP port 173, and after that, the GRE session..but the problem is that the costumer can´t make it works..&lt;/P&gt;&lt;P&gt;As an example, this is a snapshot of the nat translation:&lt;/P&gt;&lt;P&gt;ADVERTISING#sh ip nat translations  | i 148.244.244&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1329 192.168.1.132:1329 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:57  192.168.1.133:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:57&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1026 192.168.1.133:1049 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:50145 192.168.1.133:50145 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:50145 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:50145&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:23  192.168.1.134:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:23&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1114 192.168.1.134:1114 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:17376 192.168.1.134:17376 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:17376 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:17376&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1025 192.168.1.135:1077 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1054 192.168.1.138:1036 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:2   192.168.1.139:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:2&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:994 192.168.1.139:994  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:994 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:994&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1036 192.168.1.139:1052 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1268 192.168.1.139:1268 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:9   192.168.1.143:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:9&lt;/P&gt;&lt;P&gt;As you can see, there is NAT on the CPE in order to change the 192.168.1.x IP to a public ip address (source to the PPTP Server), on the server side, there is another NAT in order to have a public ip address &amp;lt;PPTP_IP_ADDRESS&amp;gt;..&lt;/P&gt;&lt;P&gt;This is the debug attached..&lt;/P&gt;&lt;P&gt;Does anyone have an idea what can be happening??im new about pptp...thank you very much in advice!&lt;/P&gt;&lt;P&gt;Alfonso&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 08:30:39 GMT</pubDate>
    <dc:creator>jresendizz</dc:creator>
    <dc:date>2020-02-21T08:30:39Z</dc:date>
    <item>
      <title>PPTP with NAT</title>
      <link>https://community.cisco.com/t5/network-security/pptp-with-nat/m-p/502151#M1055644</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;One of my costumers is connected to my Internet network (im an isp), the costumer is using dynamic nat, and on the other end, there is a PPTP server (on a hosted environment), the costumer complains that sometimes can´t connect throught the pptp tunnel, but i always see the TCP port 173, and after that, the GRE session..but the problem is that the costumer can´t make it works..&lt;/P&gt;&lt;P&gt;As an example, this is a snapshot of the nat translation:&lt;/P&gt;&lt;P&gt;ADVERTISING#sh ip nat translations  | i 148.244.244&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1329 192.168.1.132:1329 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:57  192.168.1.133:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:57&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1026 192.168.1.133:1049 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:50145 192.168.1.133:50145 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:50145 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:50145&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:23  192.168.1.134:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:23&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1114 192.168.1.134:1114 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:17376 192.168.1.134:17376 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:17376 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:17376&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1025 192.168.1.135:1077 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1054 192.168.1.138:1036 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:2   192.168.1.139:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:2&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:994 192.168.1.139:994  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:994 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:994&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1036 192.168.1.139:1052 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:3389&lt;/P&gt;&lt;P&gt;tcp &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:1268 192.168.1.139:1268 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:1723&lt;/P&gt;&lt;P&gt;gre &amp;lt;IP_ADDRESS_OUTSIDE&amp;gt;:9   192.168.1.143:256  &amp;lt;PPTP_IP_ADDRESS&amp;gt;:256 &amp;lt;PPTP_IP_ADDRESS&amp;gt;:9&lt;/P&gt;&lt;P&gt;As you can see, there is NAT on the CPE in order to change the 192.168.1.x IP to a public ip address (source to the PPTP Server), on the server side, there is another NAT in order to have a public ip address &amp;lt;PPTP_IP_ADDRESS&amp;gt;..&lt;/P&gt;&lt;P&gt;This is the debug attached..&lt;/P&gt;&lt;P&gt;Does anyone have an idea what can be happening??im new about pptp...thank you very much in advice!&lt;/P&gt;&lt;P&gt;Alfonso&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:30:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-with-nat/m-p/502151#M1055644</guid>
      <dc:creator>jresendizz</dc:creator>
      <dc:date>2020-02-21T08:30:39Z</dc:date>
    </item>
  </channel>
</rss>

