<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with Inside to DMZ Configuration and accessing external  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873090#M489005</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Looks like I've had a bit of a breakthrough...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;While testing all the DMZ IPs, I found one that worked.&amp;nbsp; As it turned out the machine that I was trying to test was a Linux VM which sits on both networks.&amp;nbsp; It looks like the server was trying to be clever and send the response back through the gateway that it knew about on the inside network.&amp;nbsp; My machine would have seen to response from an unidentified source and rejected it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Once I removed the second network/gateway, it worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Now I just have issue 2 to deal with.&amp;nbsp; PPTP on the inside not talking to PPTP servers on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chris &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Jan 2012 14:41:50 GMT</pubDate>
    <dc:creator>christopher.caruk</dc:creator>
    <dc:date>2012-01-09T14:41:50Z</dc:date>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external PPTP servers on 2811</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873087#M489002</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;I have a Cisco 2811 running Advance Enterprise v 15.1-2.&amp;nbsp; I've just configured it using ccp for internet access (on 2 lines) and a firewall.&amp;nbsp; The configuration is pretty much all default and I used the ccp wizard to create a 'medium-secure' firewall. I have 2 blocks of public IP addresses for my internal network and for the DMZ.&amp;nbsp; The 2800 is configured as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;- 2 x default routes. one to each dialer.&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;- 6 zone pairs as follows:&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp; - ccp-zp-self-out (seems to mostly work... I can ping any IP address from a console but not a hostname)&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp; - ccp-zp-in-out (works fine, both interfaces seem to be in use)&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp; - ccp-zp-in-dmz&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - which by default set to ccp-permit-dmzservice &lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - which inspects ccp-dmz-traffic &lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; - which matches group dmz_traffic and has a class map dmz-traffic&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp; - cnc-zp-dmz-out which is set to ccp-inspect. (my own zone pair to allow systems in the DMZ zone to see the internet.&amp;nbsp; This works fine.)&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp; - ccp-zp-out-dmz (works fine.&amp;nbsp; I can see my web server from any system outside my own network)&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&amp;nbsp; - ccp-zp-out-self (which, I guess allows anything permitted to get to the 2811)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Internet works from within the DMZ and in-zone.&amp;nbsp; The outside can access my dmz servers.&amp;nbsp; The inside can access most things on the outside using the firewall rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;but... I am having 2 problems that I cannot seem to figure out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Although I have the zones set up to allow the same access from in-&amp;gt;dmz as I do from out-&amp;gt;dmz and out-&amp;gt;dmz seems to work, I cannot seem to access anything in the dmz from the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;2) When setting up the firewall I ticked the box for 'allow PPTP clients to make connections from the inside' (or something like that).&amp;nbsp; I cannot seem to make a PPTP connection from my workstation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;I have scoured the internet for guides, looked through these forums &amp;amp; the cisco configuration guides and experimented all day but still cannot figure this out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Do I need a special route between the inside and dmz?&amp;nbsp; I have seem references to static routes on ASA firewalls but the command 'static (inside,dmz)...' does not work on a 2800 series router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Assistance would be appreciated.&amp;nbsp; Attached is an obfuscated config file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873087#M489002</guid>
      <dc:creator>christopher.caruk</dc:creator>
      <dc:date>2019-03-11T22:11:48Z</dc:date>
    </item>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873088#M489003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Christopher,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope you are having a great weekend!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets start working on this:&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; font-family: Arial, verdana, sans-serif;"&gt;1) Although I have the zones set up to allow the same access from in-&amp;gt;dmz as I do from out-&amp;gt;dmz and out-&amp;gt;dmz seems to work, I cannot seem to access anything in the dmz from the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style-type: none; margin-top: 0cm; margin-right: 0cm; margin-bottom: 0.0001pt; margin-left: 0cm; font-family: Arial, verdana, sans-serif;"&gt;2) When setting up the firewall I ticked the box for 'allow PPTP clients to make connections from the inside' (or something like that).&amp;nbsp; I cannot seem to make a PPTP connection from my workstation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-You have the following configured &lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;class-map type inspect match-all ccp-dmz-traffic&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;As you can see there is a match-all so this will never work because a packet will need to match all the protocols you have into this class as well the Access-group, so for this to work lets change it to&amp;nbsp; the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;class-map type inspect match-any ccp-dmz-traffic&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2-The inside users are making PPTP connections to witch zone, where is the PPTP server?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Regards,&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Please rate the post if this helps..&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Julio&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 04:01:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873088#M489003</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-09T04:01:05Z</dc:date>
    </item>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873089#M489004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Julio,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your suggestion.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RE question 1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect &lt;STRONG&gt;match-all &lt;/STRONG&gt;ccp-dmz-traffic&lt;/P&gt;&lt;P&gt; match access-group name dmz-traffic&lt;/P&gt;&lt;P&gt; match class-map ccp-dmz-protocols&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this situation, doesn't match-all mean that the host is in the ccp-dmz-traffic access-group AND the protocol is in the dmz-traffic class-map?&amp;nbsp; I CAN access both http and ssh from the outside (on one of the machines in the DMZ).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Never the less, I have tried your suggestion abd chaged this to:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect &lt;STRONG&gt;match-any&lt;/STRONG&gt; ccp-dmz-traffic&lt;/P&gt;&lt;P&gt; match access-group name dmz-traffic&lt;/P&gt;&lt;P&gt; match class-map ccp-dmz-protocols&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and it does not seem to help.&amp;nbsp; My gut feel is that the packets are not even getting there.&amp;nbsp; Could this be a routing problem?&amp;nbsp; Do I need to have a routing protocol configured to allow packets to move from the inside network to the dmz network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have asked the router to log unsuccessful attempts to get through but there does not seem to be anything in the syslog from an internal address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;RE question 2.&amp;nbsp; Users on the inside need to connect to PPTP services on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Again for the help.&lt;/P&gt;&lt;P&gt;Chris &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 13:07:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873089#M489004</guid>
      <dc:creator>christopher.caruk</dc:creator>
      <dc:date>2012-01-09T13:07:53Z</dc:date>
    </item>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873090#M489005</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Looks like I've had a bit of a breakthrough...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;While testing all the DMZ IPs, I found one that worked.&amp;nbsp; As it turned out the machine that I was trying to test was a Linux VM which sits on both networks.&amp;nbsp; It looks like the server was trying to be clever and send the response back through the gateway that it knew about on the inside network.&amp;nbsp; My machine would have seen to response from an unidentified source and rejected it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Once I removed the second network/gateway, it worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Now I just have issue 2 to deal with.&amp;nbsp; PPTP on the inside not talking to PPTP servers on the outside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Chris &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 14:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873090#M489005</guid>
      <dc:creator>christopher.caruk</dc:creator>
      <dc:date>2012-01-09T14:41:50Z</dc:date>
    </item>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873091#M489006</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great to hear that the Inside---DMZ worked...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you leave it like this to make it work?&lt;/P&gt;&lt;P&gt;class-map type inspect&lt;STRONG&gt; match-all&lt;/STRONG&gt; ccp-dmz-traffic or did you use the match-any??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PPTP issue:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all PPTP&lt;/P&gt;&lt;P&gt;match protocol pptp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect ccp-inspect&lt;/P&gt;&lt;P&gt;class type inspect PPTP&lt;/P&gt;&lt;P&gt;inspect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you give it a try and let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 18:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873091#M489006</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-09T18:07:42Z</dc:date>
    </item>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873092#M489008</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;I did try your suggested change but it did not make a difference so I reverted back to 'match-all'.&amp;nbsp; I do believe that the match-all in this situation means that the host must be in the ccp-dmz-traffic access-group AND the protocol must be in the dmz-traffic class-map but you would likely know better.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;So the short answer is, I wound up leaving it as it was.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;I have just tried your suggestion for PPTP by adding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;&lt;SPAN style="background-color: white;"&gt;class-map type inspect match-all PPTP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: white;"&gt;match protocol pptp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: white;"&gt;policy-map type inspect ccp-inspect&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: white;"&gt;class type inspect PPTP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: white;"&gt;inspect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;When I try to connect to a PPTP network, my system gets stuck at 'Verifying user name and password'.&amp;nbsp; Even after I manually cancel, Windows networking seems to continue to try to connect until I reboot.&amp;nbsp; If I disable the Cisco firewall, it works... so I am sure that this one is a configuration issue.&amp;nbsp; Very strange.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 23:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873092#M489008</guid>
      <dc:creator>christopher.caruk</dc:creator>
      <dc:date>2012-01-09T23:09:40Z</dc:date>
    </item>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873093#M489009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Chris,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any logs of the firewall drop while you attempt to make the connection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jan 2012 23:17:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873093#M489009</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-01-09T23:17:17Z</dc:date>
    </item>
    <item>
      <title>Problem with Inside to DMZ Configuration and accessing external</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873094#M489012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0cm; margin-bottom: .0001pt;"&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;I've had a number of other matters to deal with and have not been able to come back to this for a while.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Since my last writing I have also tested a fairly default configuration on an ISR 1841 using 15.1(4)M3.&amp;nbsp; It also does not seem to be letting PPTP or IPSec through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;So the question remains... How do I configure it the 2811 or 1841 to allow me to connect to external VPN servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt;"&gt;Re the suggestion above…&amp;nbsp; How do I set the Cisco to tell me what packets the firewall is dropping?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Feb 2012 00:24:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-inside-to-dmz-configuration-and-accessing-external/m-p/1873094#M489012</guid>
      <dc:creator>christopher.caruk</dc:creator>
      <dc:date>2012-02-23T00:24:55Z</dc:date>
    </item>
  </channel>
</rss>

