<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PPTP Passthrough ASA 9.x in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096181#M393043</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having the same problem in 9.1(1) which existed in 8.3(2). Here's the debug from a session:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PPTP start-control-request: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP start-control-reply: (inside:10.0.1.89/41245 &amp;lt;- outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-request: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-reply: (inside:10.0.1.89/41245 &amp;lt;- outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-reply: (inside:10.0.1.89/41245 &amp;lt;- outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP set-link-info: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP set-link-info: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP set-link-info: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inspect pptp is turned. I only have a single public IP on the outside, so dedicating a second public IP is not feasible. A solution that will work for any PPTP client on the inside would be nice but not required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Hammer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 Jan 2013 05:16:06 GMT</pubDate>
    <dc:creator>hmajidy2001</dc:creator>
    <dc:date>2013-01-15T05:16:06Z</dc:date>
    <item>
      <title>PPTP Passthrough ASA 9.x</title>
      <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096180#M393042</link>
      <description>&lt;P&gt;I recently installed a new ASA 5515-X with software version 9.1 installed.&amp;nbsp; Everything is working great except for outbound PPTP VPN connections to remote servers.&amp;nbsp; I have enabled PPTP inspection like I have with other installations but the PPTP connections keeps getting stuck at the username/password prompt.&amp;nbsp; Below is what I have from a "debug pptp" with x.x.x.x being the client IP and y.y.y.y being the remote server IP.&amp;nbsp; Any assistance would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PPTP start-control-request: (inside:x.x.x.x/51181 -&amp;gt; outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP start-control-reply: (inside:x.x.x.x/51181 &amp;lt;- outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-request: (inside:x.x.x.x/51181 -&amp;gt; outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-reply: (inside:x.x.x.x/51181 &amp;lt;- outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP set-link-info: (inside:x.x.x.x/51181 -&amp;gt; outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP clear-request: (inside:x.x.x.x/51181 &amp;lt;- outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP disconnect-notify: (inside:x.x.x.x/51181 -&amp;gt; outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP unknown-message: (inside:x.x.x.x/51181 -&amp;gt; outside:y.y.y.y/1723)&lt;/P&gt;&lt;P&gt;PPTP unknown-message: (inside:x.x.x.x/51181 &amp;lt;- outside:y.y.y.y/1723)&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:45:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096180#M393042</guid>
      <dc:creator>edatwyler</dc:creator>
      <dc:date>2019-03-12T00:45:51Z</dc:date>
    </item>
    <item>
      <title>PPTP Passthrough ASA 9.x</title>
      <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096181#M393043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Having the same problem in 9.1(1) which existed in 8.3(2). Here's the debug from a session:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PPTP start-control-request: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP start-control-reply: (inside:10.0.1.89/41245 &amp;lt;- outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-request: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-reply: (inside:10.0.1.89/41245 &amp;lt;- outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP outgoing-call-reply: (inside:10.0.1.89/41245 &amp;lt;- outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP set-link-info: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP set-link-info: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;PPTP set-link-info: (inside:10.0.1.89/41245 -&amp;gt; outside:w.x.y.z/1723)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inspect pptp is turned. I only have a single public IP on the outside, so dedicating a second public IP is not feasible. A solution that will work for any PPTP client on the inside would be nice but not required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Hammer&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Jan 2013 05:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096181#M393043</guid>
      <dc:creator>hmajidy2001</dc:creator>
      <dc:date>2013-01-15T05:16:06Z</dc:date>
    </item>
    <item>
      <title>PPTP Passthrough ASA 9.x</title>
      <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096182#M393044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am seeing this exact same issue. Is there any workaround for the problem?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 15:31:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096182#M393044</guid>
      <dc:creator>David Kron</dc:creator>
      <dc:date>2013-08-14T15:31:29Z</dc:date>
    </item>
    <item>
      <title>PPTP Passthrough ASA 9.x</title>
      <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096183#M393045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you provide your configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 16:34:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096183#M393045</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-14T16:34:04Z</dc:date>
    </item>
    <item>
      <title>PPTP Passthrough ASA 9.x</title>
      <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096184#M393046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a 5505 running 9.1(1) as far as relevant config goes, we've got pptp allowed out and have enabled pptp inspection as shown below. When a user tries to connect using a windows 7 native VPN to an outside server, I get the same debug output as the others above. On other ASAs with older firmware versions, things work fine but this particular firewall needed the later firmware for the expanded NAT functionality.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl_internal_out extended permit tcp any any eq pptp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 18:15:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096184#M393046</guid>
      <dc:creator>David Kron</dc:creator>
      <dc:date>2013-08-14T18:15:07Z</dc:date>
    </item>
    <item>
      <title>PPTP Passthrough ASA 9.x</title>
      <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096185#M393047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PPTP inspection should be doing it, certanly not expected at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show service-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do the logs tell you while the issue happens?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Aug 2013 20:51:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096185#M393047</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-14T20:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: PPTP Passthrough ASA 9.x</title>
      <link>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096186#M393048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok I finally figured out my problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The new site that was having this problem had all fresh equipment. A couple of C3750Xs, a pair of ASAs in active/passive and 3 standalone Aironet 1140s. I had been blaming the ASA for the pptp problem when in fact it had nothing to do with it all along! It was actually a problem with the freaking Aironets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;per: &lt;A _jive_internal="true" href="https://community.cisco.com/thread/1003257" rel="nofollow"&gt;https://supportforums.cisco.com/thread/1003257&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hadn't even considered this as a possibility and had happily tried my various pptp connection attempts exclusively via wifi, as had all of the users who originally reported the problem. Simply upgraded the 1140 firmware as mentioned in that thread and it all started working. Check your aironet firmware if you are using cisco wifi!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Oct 2013 16:25:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pptp-passthrough-asa-9-x/m-p/2096186#M393048</guid>
      <dc:creator>David Kron</dc:creator>
      <dc:date>2013-10-14T16:25:17Z</dc:date>
    </item>
  </channel>
</rss>

