<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CBAC PPTP outbound issue to server on same isp subnet - 2811 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cbac-pptp-outbound-issue-to-server-on-same-isp-subnet-2811/m-p/2140376#M360743</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you re-write ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 105 permit tcp any host 71.x.x.x eq 22&lt;/P&gt;&lt;P&gt;access-list 105 permit udp any host 71.x.x.x eq 5060&lt;/P&gt;&lt;P&gt;access-list 105 permit tcp any any eq 1723&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list 105 permit udp any any eq 1723&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;access-list 105 permit gre host 71.x.x.50 any&lt;/P&gt;&lt;P&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Mar 2013 06:06:24 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2013-03-26T06:06:24Z</dc:date>
    <item>
      <title>CBAC PPTP outbound issue to server on same isp subnet - 2811</title>
      <link>https://community.cisco.com/t5/network-security/cbac-pptp-outbound-issue-to-server-on-same-isp-subnet-2811/m-p/2140375#M360742</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am using MS VPN/PPTP client. This client works fine from home but not at the office. At our office, we have a 192.168.2.0 /24 subnet. We have two DSL connections from the same provider. Both of these DSL connections are in the same Class C subnet. One DSL is used for the office users and one is used for a completely, separate/isolated test environment. I need to be able to PPTP into the test environment fw (71.x.x.50) from the local office lan. I am sitting behind a 2811 using CBAC for outbound traffic and an ACL for inbound traffic. I can't even telnet to port 23 and the log only shows this generic message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;002027: Mar&amp;nbsp; 4 17:27:19.861 CST: %FW-6-SESS_AUDIT_TRAIL_START: Start pptp session: initiator (192.168.2.120:51094) -- responder (71.x.x.x:1723)&lt;BR /&gt;002028: Mar&amp;nbsp; 4 17:27:42.226 CST: %FW-6-SESS_AUDIT_TRAIL: Stop pptp session: initiator (192.168.2.120:51094) sent 364 bytes -- responder (71.x.x.x:1723) sent 352 bytes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config. Wha should I change, please?&lt;/P&gt;&lt;P&gt;ip inspect name Outbound sip&lt;BR /&gt;ip inspect name Outbound tftp&lt;BR /&gt;ip inspect name Outbound tcp&lt;BR /&gt;ip inspect name Outbound udp&lt;BR /&gt;ip inspect name Outbound icmp router-traffic&lt;BR /&gt;ip inspect name Outbound pptp audit-trail on timeout 3600&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface FastEthernet0/0&lt;BR /&gt;&amp;nbsp; ip address 71.x.x.120 255.255.255.0&lt;BR /&gt;ip access-group 105 in&lt;BR /&gt;no ip unreachables&lt;BR /&gt;ip flow ingress&lt;BR /&gt;ip flow egress&lt;BR /&gt;ip nat outside&lt;BR /&gt;ip inspect Outbound out&lt;BR /&gt;ip virtual-reassembly&lt;BR /&gt;duplex auto&lt;BR /&gt;speed auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 105 permit tcp any host 71.x.x.x eq 22&lt;BR /&gt;access-list 105 permit udp any host 71.x.x.x eq 5060&lt;BR /&gt;access-list 105 permit tcp any any eq 1723&lt;BR /&gt;access-list 105 permit gre host 71.x.x.50 any&lt;BR /&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;P&gt;access-list 175 deny&amp;nbsp;&amp;nbsp; ip 192.168.2.0 0.0.0.255 192.168.60.0 0.0.0.255&lt;BR /&gt;access-list 175 deny&amp;nbsp;&amp;nbsp; ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255&lt;BR /&gt;access-list 175 deny&amp;nbsp;&amp;nbsp; ip 192.168.2.0 0.0.0.255 192.168.3.0 0.0.0.255&lt;BR /&gt;access-list 175 permit ip 192.168.2.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ip nat inside source route-map nonat interface FastEthernet0/0 overload&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:10:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-pptp-outbound-issue-to-server-on-same-isp-subnet-2811/m-p/2140375#M360742</guid>
      <dc:creator>jacob6000</dc:creator>
      <dc:date>2019-03-12T01:10:17Z</dc:date>
    </item>
    <item>
      <title>CBAC PPTP outbound issue to server on same isp subnet - 2811</title>
      <link>https://community.cisco.com/t5/network-security/cbac-pptp-outbound-issue-to-server-on-same-isp-subnet-2811/m-p/2140376#M360743</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;could you re-write ACL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 105 permit tcp any host 71.x.x.x eq 22&lt;/P&gt;&lt;P&gt;access-list 105 permit udp any host 71.x.x.x eq 5060&lt;/P&gt;&lt;P&gt;access-list 105 permit tcp any any eq 1723&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list 105 permit udp any any eq 1723&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;access-list 105 permit gre host 71.x.x.50 any&lt;/P&gt;&lt;P&gt;access-list 105 deny&amp;nbsp;&amp;nbsp; ip any any log&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Mar 2013 06:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cbac-pptp-outbound-issue-to-server-on-same-isp-subnet-2811/m-p/2140376#M360743</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-03-26T06:06:24Z</dc:date>
    </item>
  </channel>
</rss>

