<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco 892 + PPTP clients in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-892-pptp-clients/m-p/1625007#M589965</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HI Charles-Antoine,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refrain from making multiple posts of the same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 08 Mar 2011 03:38:58 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2011-03-08T03:38:58Z</dc:date>
    <item>
      <title>Cisco 892 + PPTP clients</title>
      <link>https://community.cisco.com/t5/network-security/cisco-892-pptp-clients/m-p/1625006#M589956</link>
      <description>&lt;DIV class="jive-rendered-content"&gt;&lt;P&gt;&lt;SPAN class="value"&gt;&lt;SPAN class="pBody postableBody"&gt;We have a Cisco 891 with this configuration&amp;nbsp; below&lt;BR /&gt;&lt;BR /&gt;I&amp;nbsp;&amp;nbsp; got several computer on my lan that needs to connect to an external&amp;nbsp;&amp;nbsp; Windows server with pptp. The windows server is not mine but it works.&amp;nbsp;&amp;nbsp; The clients are using the windows connection manager. We can connect to&amp;nbsp;&amp;nbsp; the windows pptp server for hours sometimes.&lt;BR /&gt;&lt;BR /&gt;But, sometimes we&amp;nbsp;&amp;nbsp; can just connect about 3-4-5 minutes, and it auto-disconnects. Is there&amp;nbsp;&amp;nbsp; something wrong in my configuration ? I heard the cisco router is&amp;nbsp;&amp;nbsp; messing with the keepalive or the connection state.&lt;BR /&gt;&lt;BR /&gt;It seems to happens when i have more than 5-6 clients connected at the same time on the same server. &lt;BR /&gt;&lt;BR /&gt;I got theses mesages : Link to VPN failed. OR ERROR 619 OR ERROR 651&lt;BR /&gt;&lt;BR /&gt;Before,&amp;nbsp;&amp;nbsp; I had a RV042 and it worked like a charm. We were 10 on the vpn server&amp;nbsp;&amp;nbsp; and it was working. I dont see why Its not working now....&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="value"&gt;&lt;SPAN class="pBody postableBody"&gt;The errors are : Link to VPN server failed, OR ERROR 619 or ERROR 651.... (Windows 7)&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;version 15.0&lt;BR /&gt;no service pad&lt;BR /&gt;service tcp-keepalives-in&lt;BR /&gt;service tcp-keepalives-out&lt;BR /&gt;service timestamps debug datetime msec localtime show-timezone&lt;BR /&gt;service timestamps log datetime msec localtime show-timezone&lt;BR /&gt;service password-encryption&lt;BR /&gt;service sequence-numbers&lt;BR /&gt;!&lt;BR /&gt;hostname Quantis891&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login local_authen local&lt;BR /&gt;aaa authorization exec local_author local &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;clock timezone PCTime -5&lt;BR /&gt;clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip source-route&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip dhcp excluded-address 10.10.10.1&lt;BR /&gt;ip dhcp excluded-address 10.1.1.201 10.1.1.254&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool ccp-pool&lt;BR /&gt;&amp;nbsp;&amp;nbsp; import all&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.10.10.0 255.255.255.248&lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.10.10.1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; lease 0 2&lt;BR /&gt;!&lt;BR /&gt;ip dhcp pool Quantis&lt;BR /&gt;&amp;nbsp;&amp;nbsp; import all&lt;BR /&gt;&amp;nbsp;&amp;nbsp; network 10.1.1.0 255.255.255.0&lt;BR /&gt;&amp;nbsp;&amp;nbsp; dns-server 8.8.8.8 8.8.4.4 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; default-router 10.1.1.1 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; netbios-name-server 10.1.1.253 &lt;BR /&gt;&amp;nbsp;&amp;nbsp; lease infinite&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip cef&lt;BR /&gt;no ip bootp server&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;license udi pid CISCO891-K9 sn&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;object-group service Srvloc &lt;BR /&gt; description Srvloc Port 427&lt;BR /&gt; udp lt 427&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip tcp synwait-time 10&lt;BR /&gt;!&lt;BR /&gt;class-map match-any WebEmail&lt;BR /&gt; match protocol http&lt;BR /&gt; match protocol secure-http&lt;BR /&gt; match protocol smtp&lt;BR /&gt; match protocol pop3&lt;BR /&gt; match protocol dns&lt;BR /&gt; match protocol secure-pop3&lt;BR /&gt; match protocol imap&lt;BR /&gt;class-map match-any VoIP&lt;BR /&gt; match protocol skype&lt;BR /&gt;class-map match-any VPN&lt;BR /&gt; match protocol pptp&lt;BR /&gt; match protocol gre&lt;BR /&gt; match protocol l2tp&lt;BR /&gt; match protocol ipsec&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map QoS&lt;BR /&gt; class VoIP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority percent 15&lt;BR /&gt;&amp;nbsp; set dscp ef&lt;BR /&gt; class VPN&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; priority percent 40&lt;BR /&gt; class WebEmail&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; bandwidth remaining percent 40&lt;BR /&gt; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; bandwidth remaining percent 35&lt;BR /&gt;!&lt;BR /&gt;! &lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface Null0&lt;BR /&gt; no ip unreachables&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt; switchport trunk native vlan 2&lt;BR /&gt; shutdown&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1&lt;BR /&gt; shutdown&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet2&lt;BR /&gt; shutdown&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet3&lt;BR /&gt; shutdown&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet4&lt;BR /&gt; shutdown&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet5&lt;BR /&gt; shutdown&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet6&lt;BR /&gt; shutdown&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet7&lt;BR /&gt; switchport access vlan 2&lt;BR /&gt; switchport trunk native vlan 2&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet8&lt;BR /&gt; no ip address&lt;BR /&gt; no ip redirects&lt;BR /&gt; no ip unreachables&lt;BR /&gt; no ip proxy-arp&lt;BR /&gt; ip nbar protocol-discovery&lt;BR /&gt; ip flow ingress&lt;BR /&gt; ip flow egress&lt;BR /&gt; shutdown&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0&lt;BR /&gt; description $ETH-WAN$$FW_OUTSIDE$&lt;BR /&gt; bandwidth 2048&lt;BR /&gt; ip address dhcp client-id GigabitEthernet0 hostname nostromo&lt;BR /&gt; no ip redirects&lt;BR /&gt; no ip unreachables&lt;BR /&gt; no ip proxy-arp&lt;BR /&gt; ip nbar protocol-discovery&lt;BR /&gt; ip flow ingress&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt; duplex auto&lt;BR /&gt; speed auto&lt;BR /&gt; !&lt;BR /&gt; service-policy output QoS&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; description $ETH-SW-LAUNCH$$INTF-INFO-FE 1$$FW_INSIDE$&lt;BR /&gt; ip address 10.10.10.1 255.255.255.248&lt;BR /&gt; ip access-group 100 in&lt;BR /&gt; no ip redirects&lt;BR /&gt; no ip unreachables&lt;BR /&gt; no ip proxy-arp&lt;BR /&gt; ip flow ingress&lt;BR /&gt; ip tcp adjust-mss 1452&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface Vlan2&lt;BR /&gt; description $FW_INSIDE$&lt;BR /&gt; ip address 10.1.1.1 255.255.255.0&lt;BR /&gt; ip access-group 103 in&lt;BR /&gt; no ip redirects&lt;BR /&gt; no ip unreachables&lt;BR /&gt; no ip proxy-arp&lt;BR /&gt; ip nbar protocol-discovery&lt;BR /&gt; ip flow ingress&lt;BR /&gt; ip flow egress&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;interface Async1&lt;BR /&gt; no ip address&lt;BR /&gt; no ip redirects&lt;BR /&gt; no ip unreachables&lt;BR /&gt; no ip proxy-arp&lt;BR /&gt; encapsulation slip&lt;BR /&gt; !&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;ip http server&lt;BR /&gt;ip http access-class 23&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;BR /&gt;!&lt;BR /&gt;ip flow-top-talkers&lt;BR /&gt; top 10&lt;BR /&gt; sort-by bytes&lt;BR /&gt;!&lt;BR /&gt;ip nat inside source list 1 interface GigabitEthernet0 overload&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended SDM_BOOTPC&lt;BR /&gt; remark CCP_ACL Category=0&lt;BR /&gt; permit udp any any eq bootpc&lt;BR /&gt;!&lt;BR /&gt;logging trap debugging&lt;BR /&gt;logging 10.1.1.253&lt;BR /&gt;access-list 1 remark INSIDE_IF=Vlan2&lt;BR /&gt;access-list 1 remark CCP_ACL Category=2&lt;BR /&gt;access-list 1 permit 10.1.1.0 0.0.0.255&lt;BR /&gt;access-list 12 permit any&lt;BR /&gt;access-list 23 remark CCP_ACL Category=16&lt;BR /&gt;access-list 23 permit 10.1.1.0 0.0.0.255&lt;BR /&gt;access-list 23 permit 10.10.10.0 0.0.0.255&lt;BR /&gt;access-list 23 permit 10.10.10.0 0.0.0.7&lt;BR /&gt;access-list 100 remark Auto generated by SDM Management Access feature&lt;BR /&gt;access-list 100 remark CCP_ACL Category=1&lt;BR /&gt;access-list 100 permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq telnet&lt;BR /&gt;access-list 100 permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 22&lt;BR /&gt;access-list 100 permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq www&lt;BR /&gt;access-list 100 permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq 443&lt;BR /&gt;access-list 100 permit tcp 10.10.10.0 0.0.0.255 host 10.10.10.1 eq cmd&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; tcp any host 10.10.10.1 eq telnet&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; tcp any host 10.10.10.1 eq 22&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; tcp any host 10.10.10.1 eq www&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; tcp any host 10.10.10.1 eq 443&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; tcp any host 10.10.10.1 eq cmd&lt;BR /&gt;access-list 100 deny&amp;nbsp;&amp;nbsp; udp any host 10.10.10.1 eq snmp&lt;BR /&gt;access-list 100 permit ip any any&lt;BR /&gt;access-list 101 remark CCP_ACL Category=1&lt;BR /&gt;access-list 101 permit ip 10.1.1.0 0.0.0.255 any&lt;BR /&gt;access-list 101 permit ip 10.10.10.0 0.0.0.255 any&lt;BR /&gt;access-list 101 permit ip 10.10.10.0 0.0.0.7 any&lt;BR /&gt;access-list 102 remark CCP_ACL Category=1&lt;BR /&gt;access-list 102 permit ip 10.1.1.0 0.0.0.255 any&lt;BR /&gt;access-list 102 permit ip 10.10.10.0 0.0.0.255 any&lt;BR /&gt;access-list 102 permit ip 10.10.10.0 0.0.0.7 any&lt;BR /&gt;access-list 103 remark Auto generated by SDM Management Access feature&lt;BR /&gt;access-list 103 remark CCP_ACL Category=1&lt;BR /&gt;access-list 103 permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.1 eq telnet&lt;BR /&gt;access-list 103 permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.1 eq 22&lt;BR /&gt;access-list 103 permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.1 eq www&lt;BR /&gt;access-list 103 permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.1 eq 443&lt;BR /&gt;access-list 103 permit tcp 10.1.1.0 0.0.0.255 host 10.1.1.1 eq cmd&lt;BR /&gt;access-list 103 permit tcp any any eq 1723&lt;BR /&gt;access-list 103 remark GRE&lt;BR /&gt;access-list 103 permit gre any any&lt;BR /&gt;access-list 103 permit udp any any eq isakmp&lt;BR /&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any any eq 427&lt;BR /&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any host 10.1.1.1 eq telnet&lt;BR /&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any host 10.1.1.1 eq 22&lt;BR /&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any host 10.1.1.1 eq www&lt;BR /&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any host 10.1.1.1 eq 443&lt;BR /&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; tcp any host 10.1.1.1 eq cmd&lt;BR /&gt;access-list 103 deny&amp;nbsp;&amp;nbsp; udp any host 10.1.1.1 eq snmp&lt;BR /&gt;access-list 103 permit ip any any&lt;BR /&gt;no cdp run&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:02:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-892-pptp-clients/m-p/1625006#M589956</guid>
      <dc:creator>clementca</dc:creator>
      <dc:date>2019-03-11T20:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco 892 + PPTP clients</title>
      <link>https://community.cisco.com/t5/network-security/cisco-892-pptp-clients/m-p/1625007#M589965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HI Charles-Antoine,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refrain from making multiple posts of the same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 Mar 2011 03:38:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-892-pptp-clients/m-p/1625007#M589965</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2011-03-08T03:38:58Z</dc:date>
    </item>
  </channel>
</rss>

