<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1841 Border Router &amp; Pix 501 -721 PPTP error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479218#M535274</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I pounded away at this for a good couple of hours. Perseverance payed off. I was limited to one IP address because the inet provider here is totally unresponsive to my request for a second IP. This just had to work. In the configs I am using private addresses on both sides of the tunnel,  but that will change once this goes production. (next week)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am happy to say that I am successfully pushing/Nat'ing PPTP through the 1841 to the Outside of the pix and I only have one external IP. The test PPTP tunnel is to the 1841 outside address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static statment handles the 1723, and the ACL handles the GRE push through/translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the enclosed attachments for a sanity check. But I was able to ping, map drives and copy a file. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know in your email you said there is no way around it, but I think I found a way around it that appears to be working well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know what you think. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Jul 2005 05:49:53 GMT</pubDate>
    <dc:creator>mbalasko</dc:creator>
    <dc:date>2005-07-20T05:49:53Z</dc:date>
    <item>
      <title>1841 Border Router &amp; Pix 501 -721 PPTP error</title>
      <link>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479215#M535266</link>
      <description>&lt;P&gt;I hope someone can help me here. I have an 1841 Border router with a pix 501 behind it. I am using the 1841 to handle PAT and allowing the pix to handle the VPN terminations for remote users. The users are going to be using WinXP for PPTP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tested the pix and PPTP is working correctly on it. (I plugged into it via an xover cable and launched my client and the tunnel was established and behaved as expected.)  When I plug the Pix outside into my 1841 inside port is when things break. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I get a -721 error on the client and it basically hangs at verify username and pw. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I launch the tunnel from the client I see this on the pix.(Tried it a few times) (There is no nat or pat being performed on the pix. ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tnl 26 PPTP: Tunnel created; peer initiated&lt;/P&gt;&lt;P&gt;Tnl 26 PPTP: SCCRQ-ok -&amp;gt; state change wt-sccrq to estabd&lt;/P&gt;&lt;P&gt;Tnl/Cl 26/26 PPTP: l2x store session: tunnel id 26, session id 26, hash_ix=26&lt;/P&gt;&lt;P&gt;Tnl/Cl 26/26 PPTP: vacc-ok -&amp;gt; state change wt-vacc to estabd&lt;/P&gt;&lt;P&gt;Tnl/Cl 26/26 PPTP: ClearReq -&amp;gt; state change estabd to terminal&lt;/P&gt;&lt;P&gt;Tnl/Cl 26/26 PPTP: Destroying session&lt;/P&gt;&lt;P&gt;Tnl 26 PPTP: no-sess -&amp;gt; state change estabd to wt-stprp&lt;/P&gt;&lt;P&gt;Tnl 26 PPTP: StopCCRQ -&amp;gt; state change wt-stprp to wt-stprp&lt;/P&gt;&lt;P&gt;Tnl 26 PPTP: Destroy tunnel&lt;/P&gt;&lt;P&gt;Tnl 27 PPTP: Tunnel created; peer initiated&lt;/P&gt;&lt;P&gt;Tnl 27 PPTP: SCCRQ-ok -&amp;gt; state change wt-sccrq to estabd&lt;/P&gt;&lt;P&gt;Tnl/Cl 27/27 PPTP: l2x store session: tunnel id 27, session id 27, hash_ix=27&lt;/P&gt;&lt;P&gt;Tnl/Cl 27/27 PPTP: vacc-ok -&amp;gt; state change wt-vacc to estabd&lt;/P&gt;&lt;P&gt;Tnl/Cl 27/27 PPTP: ClearReq -&amp;gt; state change estabd to terminal&lt;/P&gt;&lt;P&gt;Tnl/Cl 27/27 PPTP: Destroying session&lt;/P&gt;&lt;P&gt;Tnl 27 PPTP: no-sess -&amp;gt; state change estabd to wt-stprp&lt;/P&gt;&lt;P&gt;Tnl 27 PPTP: StopCCRQ -&amp;gt; state change wt-stprp to wt-stprp&lt;/P&gt;&lt;P&gt;Tnl 27 PPTP: Destroy tunnel&lt;/P&gt;&lt;P&gt;Tnl 28 PPTP: Tunnel created; peer initiated&lt;/P&gt;&lt;P&gt;Tnl 28 PPTP: SCCRQ-ok -&amp;gt; state change wt-sccrq to estabd&lt;/P&gt;&lt;P&gt;Tnl/Cl 28/28 PPTP: l2x store session: tunnel id 28, session id 28, hash_ix=28&lt;/P&gt;&lt;P&gt;Tnl/Cl 28/28 PPTP: vacc-ok -&amp;gt; state change wt-vacc to estabd&lt;/P&gt;&lt;P&gt;Tnl/Cl 28/28 PPTP: ClearReq -&amp;gt; state change estabd to terminal&lt;/P&gt;&lt;P&gt;Tnl/Cl 28/28 PPTP: Destroying session&lt;/P&gt;&lt;P&gt;Tnl 28 PPTP: no-sess -&amp;gt; state change estabd to wt-stprp&lt;/P&gt;&lt;P&gt;Tnl 28 PPTP: StopCCRQ -&amp;gt; state change wt-stprp to wt-stprp&lt;/P&gt;&lt;P&gt;Tnl 28 PPTP: Destroy tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the 1841 I see the translations get built.(I think) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;panlig_border_1841#sho ip nat trans&lt;/P&gt;&lt;P&gt;Pro Inside global      Inside local       Outside local      Outside global&lt;/P&gt;&lt;P&gt;tcp 10.69.1.250:23     10.69.1.250:23     10.69.1.30:1233    10.69.1.30:1233&lt;/P&gt;&lt;P&gt;tcp 10.69.1.250:4399   172.16.5.250:4399  10.69.1.30:445     10.69.1.30:445&lt;/P&gt;&lt;P&gt;tcp 10.69.1.250:1723   192.168.99.249:1723 10.69.1.30:1100   10.69.1.30:1100&lt;/P&gt;&lt;P&gt;gre 10.69.1.250:32768  192.168.99.249:32768 10.69.1.30:32768 10.69.1.30:32768&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see the GRE_PPTP ACL gte hits(Except GRE weird?) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Extended IP access list GRE_PPTP&lt;/P&gt;&lt;P&gt;    10 permit gre any any log&lt;/P&gt;&lt;P&gt;    20 permit tcp any any eq 1723 log (4 matches)&lt;/P&gt;&lt;P&gt;    21 permit tcp any any established (1548 matches)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used to have a ip nat source static 1723 statement in there, but I couldn't even get that to get me to a 721 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;error. It basically gave me an 800 vpn server not responding, and I'd never see the pptp request hit the pix. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need any more info to help. I'll buy the beers:) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1841-outside address 10.69.1.250 - Default route to 10.69.1.254 its upstream neighbor.&lt;/P&gt;&lt;P&gt;1841- inside to pix- 192.168.99.254&lt;/P&gt;&lt;P&gt;Pix 501-outside- 192.168.99.249&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PPTP address pool- 172.16.253.10-50&lt;/P&gt;&lt;P&gt;Internal addresses behind the pix- 172.161.1.0,172.16.2.0 and 172.16.3.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1841 Software (C1841-ADVSECURITYK9-M), Version 12.4(1a), RELEASE SOFTWARE (fc2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1841 Router Config-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:16:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479215#M535266</guid>
      <dc:creator>mbalasko</dc:creator>
      <dc:date>2020-02-21T08:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: 1841 Border Router &amp; Pix 501 -721 PPTP error</title>
      <link>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479216#M535270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure what you're trying to do with the "ip nat destination" commands in there.  To pass PPTP traffic through the router to the PIX's outside interface you need a static NAT translation (not PAT) for th ePIX's outside address, only then will the router pass both the TCP/1723 AND the GRE packets through correctly.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove all the NAT stuff you currently have for the PPTP connection, and add just the following:&lt;/P&gt;&lt;P&gt;&lt;B&gt;&lt;/B&gt;&lt;/P&gt;&lt;P&gt;ip nat inside source static 192.168.99.249 10.69.1.251&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your users will then connect to 10.69.1.251 on their PPTP connection and the router will forward those packets straight thru to the PIX.  The connection should then proceed correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll notice that you need a second external IP address for this, unfortunately there's no way around this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2005 00:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479216#M535270</guid>
      <dc:creator>gfullage</dc:creator>
      <dc:date>2005-07-18T00:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: 1841 Border Router &amp; Pix 501 -721 PPTP error</title>
      <link>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479217#M535272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, so I have a serious headache. I pounded at this for a few more hours and came up with.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip nat pool panlight1841 10.69.1.250 10.69.1.250 netmask 255.255.255.0 type rotary&lt;/P&gt;&lt;P&gt;ip nat pool PIX 192.168.99.249 192.168.99.249 netmask 255.255.255.0 type rotary&lt;/P&gt;&lt;P&gt;ip nat inside source list all-out interface FastEthernet0/0 overload&lt;/P&gt;&lt;P&gt;ip nat inside source static tcp 192.168.99.249 1723 interface FastEthernet0/0 1723&lt;/P&gt;&lt;P&gt;ip nat inside source static udp 192.168.99.249 500 interface FastEthernet0/0 500&lt;/P&gt;&lt;P&gt;ip nat inside destination list GRE_PPTP pool PIX&lt;/P&gt;&lt;P&gt;ip nat inside destination list rem_manage pool panlight1841&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list standard all-out&lt;/P&gt;&lt;P&gt; permit any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip access-list extended GRE_PPTP&lt;/P&gt;&lt;P&gt; permit gre any any log&lt;/P&gt;&lt;P&gt; permit tcp any any established&lt;/P&gt;&lt;P&gt; deny   ip any any log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I think it works!!!! I authenticate and I am also able to ping the inside router. (The router that is beyond the  pix's inside interface.) I'll see tomorrow and figure out if I can actually do anything like telnet or map a drive. Its late. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help, and I'll post if this thing actually works.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2005 04:56:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479217#M535272</guid>
      <dc:creator>mbalasko</dc:creator>
      <dc:date>2005-07-18T04:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: 1841 Border Router &amp; Pix 501 -721 PPTP error</title>
      <link>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479218#M535274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I pounded away at this for a good couple of hours. Perseverance payed off. I was limited to one IP address because the inet provider here is totally unresponsive to my request for a second IP. This just had to work. In the configs I am using private addresses on both sides of the tunnel,  but that will change once this goes production. (next week)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am happy to say that I am successfully pushing/Nat'ing PPTP through the 1841 to the Outside of the pix and I only have one external IP. The test PPTP tunnel is to the 1841 outside address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static statment handles the 1723, and the ACL handles the GRE push through/translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See the enclosed attachments for a sanity check. But I was able to ping, map drives and copy a file. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know in your email you said there is no way around it, but I think I found a way around it that appears to be working well. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know what you think. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Jul 2005 05:49:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/1841-border-router-pix-501-721-pptp-error/m-p/479218#M535274</guid>
      <dc:creator>mbalasko</dc:creator>
      <dc:date>2005-07-20T05:49:53Z</dc:date>
    </item>
  </channel>
</rss>

