<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 892 Router PPTP VPN Help Please in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/892-router-pptp-vpn-help-please/m-p/2435995#M268804</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've just been trying to configure my 892 router to accept PPTP connections (not passthrough but it being the PPTP server) but I'm continuously getting 619 errors. I've tried multiple different configurations and I'm just hitting a brick wall. I was hoping someone could take a quick look for me please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not the normal administrator of this appliance and have not set up anything other than setting up user2 &amp;amp; user3 along with the PPTP settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The parts i've mainly been changing are the " ip unnumbered GigabitEthernet0", I've been changin between that and VLAN1 as the interfaces I'm tying it to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User3 &amp;amp; User4 are the two users I want to connect with. It might also be good to add I'm testing from a Windows 7 PC which can successfully make PPTP VPN's to other servers external to my current location, but they are all windows based, I have no cisco devices to test from. Also the end configuration this router will be used for voip phones to make pptp connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config (IP addresses and some information changed for anonimity purposes):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 9077 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec localtime&lt;/P&gt;&lt;P&gt;service timestamps log datetime localtime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Generic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging buffered 51200&lt;/P&gt;&lt;P&gt;enable secret 4 jhfkdjgfdf87687f687g67yfdjhfjd&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clock timezone ********&lt;/P&gt;&lt;P&gt;clock summer-time ****** recurring last Sun Sep 2:00 1 Sun Apr 3:&lt;/P&gt;&lt;P&gt;crypto pki token default removal timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;ip inspect udp idle-time 300&lt;/P&gt;&lt;P&gt;ip inspect tcp max-incomplete host 100 block-time 0&lt;/P&gt;&lt;P&gt;ip inspect name firewall tcp&lt;/P&gt;&lt;P&gt;ip inspect name firewall udp&lt;/P&gt;&lt;P&gt;ip inspect name firewall h323&lt;/P&gt;&lt;P&gt;ip inspect name firewall rcmd&lt;/P&gt;&lt;P&gt;ip inspect name firewall realaudio&lt;/P&gt;&lt;P&gt;ip inspect name firewall streamworks&lt;/P&gt;&lt;P&gt;ip inspect name firewall vdolive&lt;/P&gt;&lt;P&gt;ip inspect name firewall sqlnet&lt;/P&gt;&lt;P&gt;ip inspect name firewall tftp&lt;/P&gt;&lt;P&gt;ip inspect name firewall ftp&lt;/P&gt;&lt;P&gt;ip inspect name firewall icmp&lt;/P&gt;&lt;P&gt;ip inspect name firewall sip&lt;/P&gt;&lt;P&gt;ip inspect name firewall fragment maximum 256 timeout 1&lt;/P&gt;&lt;P&gt;ip inspect name firewall netshow&lt;/P&gt;&lt;P&gt;ip inspect name firewall rtsp&lt;/P&gt;&lt;P&gt;ip inspect name firewall pptp&lt;/P&gt;&lt;P&gt;ip inspect name firewall skinny&lt;/P&gt;&lt;P&gt;no ipv6 cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;vpdn enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn-group 1&lt;/P&gt;&lt;P&gt; ! Default PPTP VPDN group&lt;/P&gt;&lt;P&gt; accept-dialin&lt;/P&gt;&lt;P&gt;&amp;nbsp; protocol pptp&lt;/P&gt;&lt;P&gt;&amp;nbsp; virtual-template 1&lt;/P&gt;&lt;P&gt; l2tp tunnel timeout no-session 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;license udi pid CISCO892-K9 sn **************&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username user1 privilege 15 secret 4 kjlghigyftuf867687ruygiygiyg&lt;/P&gt;&lt;P&gt;username user2 secret 4 fSpgIsbY.iggiyfiyyrtdd5768979yhjgjg&lt;/P&gt;&lt;P&gt;username user3 password 7 kgjggig876r5f6gi&lt;/P&gt;&lt;P&gt;username user4 password 7 khgvkhftuctcr577y9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;track 100 ip sla 100 reachability&lt;/P&gt;&lt;P&gt; delay down 15 up 30&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; encr aes&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 28800&lt;/P&gt;&lt;P&gt;crypto isakmp key generic address 111.111.111.111&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set generic esp-aes esp-sha-hmac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map Connection1 10 ipsec-isakmp&lt;/P&gt;&lt;P&gt; set peer 111.111.111.111&lt;/P&gt;&lt;P&gt; set transform-set generic&lt;/P&gt;&lt;P&gt; match address 106&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BRI0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; encapsulation hdlc&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; isdn termination multidrop&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet2&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet3&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet4&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet5&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet6&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet7&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet8&lt;/P&gt;&lt;P&gt; description Net1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; pppoe-client dial-pool-number 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Virtual-Template1&lt;/P&gt;&lt;P&gt; ip unnumbered GigabitEthernet0&lt;/P&gt;&lt;P&gt; peer default ip address pool phonepptp&lt;/P&gt;&lt;P&gt; no keepalive&lt;/P&gt;&lt;P&gt; ppp encrypt mppe 128&lt;/P&gt;&lt;P&gt; ppp authentication ms-chap ms-chap-v2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0&lt;/P&gt;&lt;P&gt; description Net2&lt;/P&gt;&lt;P&gt; ip address 192.168.200.2 255.255.255.252&lt;/P&gt;&lt;P&gt; ip access-group 102 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect firewall out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; crypto map Connection1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description LAN&lt;/P&gt;&lt;P&gt; ip address 172.16.4.3 255.255.255.0&lt;/P&gt;&lt;P&gt; ip access-group 103 in&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; ip policy route-map Connection2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dialer1&lt;/P&gt;&lt;P&gt; description WAN1 Net1&lt;/P&gt;&lt;P&gt; mtu 1492&lt;/P&gt;&lt;P&gt; ip address negotiated&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect firewall out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1440&lt;/P&gt;&lt;P&gt; dialer pool 1&lt;/P&gt;&lt;P&gt; dialer-group 1&lt;/P&gt;&lt;P&gt; ppp authentication pap callin&lt;/P&gt;&lt;P&gt; ppp pap sent-username generic password 7 ggkdfhdty6587676565&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip local pool phonepptp 172.16.4.160 172.16.4.169&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;ip nat translation tcp-timeout 30&lt;/P&gt;&lt;P&gt;ip nat translation udp-timeout 30&lt;/P&gt;&lt;P&gt;ip nat translation icmp-timeout 30&lt;/P&gt;&lt;P&gt;ip nat inside source route-map Net2 interface GigabitEthernet0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map Net1 interface Dialer1 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.205 25 192.168.200.2 25 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.205 443 192.168.200.2 443 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.205 587 192.168.200.2 587 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.204 3389 192.168.200.2 3389 extendable&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.200.1 10 track 100&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer1 251&lt;/P&gt;&lt;P&gt;ip route 10.0.0.0 255.255.255.0 172.16.4.19&lt;/P&gt;&lt;P&gt;ip route 100.30.40.1 255.255.255.255 192.168.200.1 permanent&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended NSServices&lt;/P&gt;&lt;P&gt; permit tcp any any eq telnet&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip sla 100&lt;/P&gt;&lt;P&gt; icmp-echo 100.30.40.1 source-interface GigabitEthernet0&lt;/P&gt;&lt;P&gt; threshold 500&lt;/P&gt;&lt;P&gt; timeout 500&lt;/P&gt;&lt;P&gt; frequency 5&lt;/P&gt;&lt;P&gt;ip sla schedule 100 life forever start-time now&lt;/P&gt;&lt;P&gt;access-list 2 remark Where management can be done from&lt;/P&gt;&lt;P&gt;access-list 2 permit 111.111.111.112&lt;/P&gt;&lt;P&gt;access-list 2 permit 172.16.4.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 101 remark Traffic allowed to enter the router from Net1 WAN&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 0.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 10.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 127.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 169.254.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 172.16.0.0 0.15.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 192.0.2.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 192.168.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 198.18.0.0 0.1.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 224.0.0.0 0.15.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip any host 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 111.111.111.112 any eq telnet&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any any eq 1723&lt;/P&gt;&lt;P&gt;access-list 101 permit gre any any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; icmp any any echo&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;access-list 102 remark Traffic allowed to enter the router from Net2 WAN&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 0.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 10.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 127.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 169.254.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 192.0.2.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 192.168.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 198.18.0.0 0.1.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 224.0.0.0 0.15.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip any host 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp host 111.111.111.112 any eq telnet&lt;/P&gt;&lt;P&gt;access-list 102 permit ip host 111.111.111.111 any&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 587&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 443&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 3389&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 1723&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 500&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any any eq isakmp&lt;/P&gt;&lt;P&gt;access-list 102 permit gre any any&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any packet-too-big&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any traceroute&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any administratively-prohibited&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any echo&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;access-list 103 remark Traffic allowed to enter the router from the Ethernet&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any host 172.16.4.3&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any 192.168.50.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any 10.0.0.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any host 172.16.4.255&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq tftp log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 0.0.0.0 0.255.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 10.0.0.0 0.255.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 127.0.0.0 0.255.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 169.254.0.0 0.0.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 172.16.0.0 0.15.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 192.0.2.0 0.0.0.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 172.16.4 0.0.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 198.18.0.0 0.1.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq 135 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any any eq 135 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq netbios-ns log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq netbios-dgm log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any any eq 445 log&lt;/P&gt;&lt;P&gt;access-list 103 permit ip 172.16.4.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any host 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip 172.16.4.0 0.0.0.255 192.168.50.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 105 permit ip 172.16.4.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 106 permit ip 172.16.4.0 0.0.0.255 192.168.50.0 0.0.0.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map Net1 permit 10&lt;/P&gt;&lt;P&gt; match interface Dialer1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map Connection2 permit 10&lt;/P&gt;&lt;P&gt; match ip address NSServices&lt;/P&gt;&lt;P&gt; set interface Dialer1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map Net2 permit 10&lt;/P&gt;&lt;P&gt; match ip address 105&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mgcp profile default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 120 0&lt;/P&gt;&lt;P&gt; password 7 ,jhgghdtye655687687&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 2 in&lt;/P&gt;&lt;P&gt; exec-timeout 120 0&lt;/P&gt;&lt;P&gt; password 7 jhhjftydrye534547656&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt; transport input telnet ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 03:52:19 GMT</pubDate>
    <dc:creator>damo007nz</dc:creator>
    <dc:date>2019-03-12T03:52:19Z</dc:date>
    <item>
      <title>892 Router PPTP VPN Help Please</title>
      <link>https://community.cisco.com/t5/network-security/892-router-pptp-vpn-help-please/m-p/2435995#M268804</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've just been trying to configure my 892 router to accept PPTP connections (not passthrough but it being the PPTP server) but I'm continuously getting 619 errors. I've tried multiple different configurations and I'm just hitting a brick wall. I was hoping someone could take a quick look for me please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not the normal administrator of this appliance and have not set up anything other than setting up user2 &amp;amp; user3 along with the PPTP settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The parts i've mainly been changing are the " ip unnumbered GigabitEthernet0", I've been changin between that and VLAN1 as the interfaces I'm tying it to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User3 &amp;amp; User4 are the two users I want to connect with. It might also be good to add I'm testing from a Windows 7 PC which can successfully make PPTP VPN's to other servers external to my current location, but they are all windows based, I have no cisco devices to test from. Also the end configuration this router will be used for voip phones to make pptp connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config (IP addresses and some information changed for anonimity purposes):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 9077 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;service timestamps debug datetime msec localtime&lt;/P&gt;&lt;P&gt;service timestamps log datetime localtime&lt;/P&gt;&lt;P&gt;service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Generic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;boot-start-marker&lt;/P&gt;&lt;P&gt;boot-end-marker&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;logging buffered 51200&lt;/P&gt;&lt;P&gt;enable secret 4 jhfkdjgfdf87687f687g67yfdjhfjd&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;clock timezone ********&lt;/P&gt;&lt;P&gt;clock summer-time ****** recurring last Sun Sep 2:00 1 Sun Apr 3:&lt;/P&gt;&lt;P&gt;crypto pki token default removal timeout 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip source-route&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip cef&lt;/P&gt;&lt;P&gt;ip inspect udp idle-time 300&lt;/P&gt;&lt;P&gt;ip inspect tcp max-incomplete host 100 block-time 0&lt;/P&gt;&lt;P&gt;ip inspect name firewall tcp&lt;/P&gt;&lt;P&gt;ip inspect name firewall udp&lt;/P&gt;&lt;P&gt;ip inspect name firewall h323&lt;/P&gt;&lt;P&gt;ip inspect name firewall rcmd&lt;/P&gt;&lt;P&gt;ip inspect name firewall realaudio&lt;/P&gt;&lt;P&gt;ip inspect name firewall streamworks&lt;/P&gt;&lt;P&gt;ip inspect name firewall vdolive&lt;/P&gt;&lt;P&gt;ip inspect name firewall sqlnet&lt;/P&gt;&lt;P&gt;ip inspect name firewall tftp&lt;/P&gt;&lt;P&gt;ip inspect name firewall ftp&lt;/P&gt;&lt;P&gt;ip inspect name firewall icmp&lt;/P&gt;&lt;P&gt;ip inspect name firewall sip&lt;/P&gt;&lt;P&gt;ip inspect name firewall fragment maximum 256 timeout 1&lt;/P&gt;&lt;P&gt;ip inspect name firewall netshow&lt;/P&gt;&lt;P&gt;ip inspect name firewall rtsp&lt;/P&gt;&lt;P&gt;ip inspect name firewall pptp&lt;/P&gt;&lt;P&gt;ip inspect name firewall skinny&lt;/P&gt;&lt;P&gt;no ipv6 cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;multilink bundle-name authenticated&lt;/P&gt;&lt;P&gt;vpdn enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;vpdn-group 1&lt;/P&gt;&lt;P&gt; ! Default PPTP VPDN group&lt;/P&gt;&lt;P&gt; accept-dialin&lt;/P&gt;&lt;P&gt;&amp;nbsp; protocol pptp&lt;/P&gt;&lt;P&gt;&amp;nbsp; virtual-template 1&lt;/P&gt;&lt;P&gt; l2tp tunnel timeout no-session 15&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;license udi pid CISCO892-K9 sn **************&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;username user1 privilege 15 secret 4 kjlghigyftuf867687ruygiygiyg&lt;/P&gt;&lt;P&gt;username user2 secret 4 fSpgIsbY.iggiyfiyyrtdd5768979yhjgjg&lt;/P&gt;&lt;P&gt;username user3 password 7 kgjggig876r5f6gi&lt;/P&gt;&lt;P&gt;username user4 password 7 khgvkhftuctcr577y9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;track 100 ip sla 100 reachability&lt;/P&gt;&lt;P&gt; delay down 15 up 30&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt; encr aes&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt; lifetime 28800&lt;/P&gt;&lt;P&gt;crypto isakmp key generic address 111.111.111.111&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set generic esp-aes esp-sha-hmac&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;crypto map Connection1 10 ipsec-isakmp&lt;/P&gt;&lt;P&gt; set peer 111.111.111.111&lt;/P&gt;&lt;P&gt; set transform-set generic&lt;/P&gt;&lt;P&gt; match address 106&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface BRI0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; encapsulation hdlc&lt;/P&gt;&lt;P&gt; shutdown&lt;/P&gt;&lt;P&gt; isdn termination multidrop&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet0&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet2&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet3&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet4&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet5&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet6&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet7&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface FastEthernet8&lt;/P&gt;&lt;P&gt; description Net1&lt;/P&gt;&lt;P&gt; no ip address&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; pppoe-client dial-pool-number 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Virtual-Template1&lt;/P&gt;&lt;P&gt; ip unnumbered GigabitEthernet0&lt;/P&gt;&lt;P&gt; peer default ip address pool phonepptp&lt;/P&gt;&lt;P&gt; no keepalive&lt;/P&gt;&lt;P&gt; ppp encrypt mppe 128&lt;/P&gt;&lt;P&gt; ppp authentication ms-chap ms-chap-v2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0&lt;/P&gt;&lt;P&gt; description Net2&lt;/P&gt;&lt;P&gt; ip address 192.168.200.2 255.255.255.252&lt;/P&gt;&lt;P&gt; ip access-group 102 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect firewall out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; duplex auto&lt;/P&gt;&lt;P&gt; speed auto&lt;/P&gt;&lt;P&gt; crypto map Connection1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt; description LAN&lt;/P&gt;&lt;P&gt; ip address 172.16.4.3 255.255.255.0&lt;/P&gt;&lt;P&gt; ip access-group 103 in&lt;/P&gt;&lt;P&gt; ip nat inside&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; ip policy route-map Connection2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Dialer1&lt;/P&gt;&lt;P&gt; description WAN1 Net1&lt;/P&gt;&lt;P&gt; mtu 1492&lt;/P&gt;&lt;P&gt; ip address negotiated&lt;/P&gt;&lt;P&gt; ip access-group 101 in&lt;/P&gt;&lt;P&gt; ip nat outside&lt;/P&gt;&lt;P&gt; ip inspect firewall out&lt;/P&gt;&lt;P&gt; ip virtual-reassembly in&lt;/P&gt;&lt;P&gt; encapsulation ppp&lt;/P&gt;&lt;P&gt; ip tcp adjust-mss 1440&lt;/P&gt;&lt;P&gt; dialer pool 1&lt;/P&gt;&lt;P&gt; dialer-group 1&lt;/P&gt;&lt;P&gt; ppp authentication pap callin&lt;/P&gt;&lt;P&gt; ppp pap sent-username generic password 7 ggkdfhdty6587676565&lt;/P&gt;&lt;P&gt; no cdp enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip local pool phonepptp 172.16.4.160 172.16.4.169&lt;/P&gt;&lt;P&gt;ip forward-protocol nd&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip http server&lt;/P&gt;&lt;P&gt;no ip http secure-server&lt;/P&gt;&lt;P&gt;ip nat translation tcp-timeout 30&lt;/P&gt;&lt;P&gt;ip nat translation udp-timeout 30&lt;/P&gt;&lt;P&gt;ip nat translation icmp-timeout 30&lt;/P&gt;&lt;P&gt;ip nat inside source route-map Net2 interface GigabitEthernet0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source route-map Net1 interface Dialer1 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.205 25 192.168.200.2 25 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.205 443 192.168.200.2 443 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.205 587 192.168.200.2 587 extendable&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 172.16.4.204 3389 192.168.200.2 3389 extendable&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.200.1 10 track 100&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 Dialer1 251&lt;/P&gt;&lt;P&gt;ip route 10.0.0.0 255.255.255.0 172.16.4.19&lt;/P&gt;&lt;P&gt;ip route 100.30.40.1 255.255.255.255 192.168.200.1 permanent&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended NSServices&lt;/P&gt;&lt;P&gt; permit tcp any any eq telnet&lt;/P&gt;&lt;P&gt; deny&amp;nbsp;&amp;nbsp; ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip sla 100&lt;/P&gt;&lt;P&gt; icmp-echo 100.30.40.1 source-interface GigabitEthernet0&lt;/P&gt;&lt;P&gt; threshold 500&lt;/P&gt;&lt;P&gt; timeout 500&lt;/P&gt;&lt;P&gt; frequency 5&lt;/P&gt;&lt;P&gt;ip sla schedule 100 life forever start-time now&lt;/P&gt;&lt;P&gt;access-list 2 remark Where management can be done from&lt;/P&gt;&lt;P&gt;access-list 2 permit 111.111.111.112&lt;/P&gt;&lt;P&gt;access-list 2 permit 172.16.4.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 101 remark Traffic allowed to enter the router from Net1 WAN&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 0.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 10.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 127.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 169.254.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 172.16.0.0 0.15.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 192.0.2.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 192.168.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 198.18.0.0 0.1.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip 224.0.0.0 0.15.255.255 any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip any host 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp host 111.111.111.112 any eq telnet&lt;/P&gt;&lt;P&gt;access-list 101 permit tcp any any eq 1723&lt;/P&gt;&lt;P&gt;access-list 101 permit gre any any&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; icmp any any echo&lt;/P&gt;&lt;P&gt;access-list 101 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;access-list 102 remark Traffic allowed to enter the router from Net2 WAN&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 0.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 10.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 127.0.0.0 0.255.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 169.254.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 192.0.2.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 192.168.0.0 0.0.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 198.18.0.0 0.1.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip 224.0.0.0 0.15.255.255 any&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip any host 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp host 111.111.111.112 any eq telnet&lt;/P&gt;&lt;P&gt;access-list 102 permit ip host 111.111.111.111 any&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq smtp&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 587&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 443&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 3389&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 1723&lt;/P&gt;&lt;P&gt;access-list 102 permit tcp any any eq 500&lt;/P&gt;&lt;P&gt;access-list 102 permit udp any any eq isakmp&lt;/P&gt;&lt;P&gt;access-list 102 permit gre any any&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any packet-too-big&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any traceroute&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any administratively-prohibited&lt;/P&gt;&lt;P&gt;access-list 102 permit icmp any any echo&lt;/P&gt;&lt;P&gt;access-list 102 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;access-list 103 remark Traffic allowed to enter the router from the Ethernet&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any host 172.16.4.3&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any 192.168.50.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any 10.0.0.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any host 172.16.4.255&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq tftp log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 0.0.0.0 0.255.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 10.0.0.0 0.255.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 127.0.0.0 0.255.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 169.254.0.0 0.0.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 172.16.0.0 0.15.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 192.0.2.0 0.0.0.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 172.16.4 0.0.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any 198.18.0.0 0.1.255.255 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq 135 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any any eq 135 log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq netbios-ns log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq netbios-dgm log&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any any eq 445 log&lt;/P&gt;&lt;P&gt;access-list 103 permit ip 172.16.4.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 103 permit ip any host 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip 172.16.4.0 0.0.0.255 192.168.50.0 0.0.0.255&lt;/P&gt;&lt;P&gt;access-list 105 permit ip 172.16.4.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 106 permit ip 172.16.4.0 0.0.0.255 192.168.50.0 0.0.0.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map Net1 permit 10&lt;/P&gt;&lt;P&gt; match interface Dialer1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map Connection2 permit 10&lt;/P&gt;&lt;P&gt; match ip address NSServices&lt;/P&gt;&lt;P&gt; set interface Dialer1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route-map Net2 permit 10&lt;/P&gt;&lt;P&gt; match ip address 105&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;control-plane&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;mgcp profile default&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt; exec-timeout 120 0&lt;/P&gt;&lt;P&gt; password 7 ,jhgghdtye655687687&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; access-class 2 in&lt;/P&gt;&lt;P&gt; exec-timeout 120 0&lt;/P&gt;&lt;P&gt; password 7 jhhjftydrye534547656&lt;/P&gt;&lt;P&gt; login local&lt;/P&gt;&lt;P&gt; transport input telnet ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:52:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/892-router-pptp-vpn-help-please/m-p/2435995#M268804</guid>
      <dc:creator>damo007nz</dc:creator>
      <dc:date>2019-03-12T03:52:19Z</dc:date>
    </item>
  </channel>
</rss>

