<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: l2tp/ipsec through a PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-through-a-pix/m-p/134989#M607418</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to make sure that:&lt;/P&gt;&lt;P&gt;1 - you have a static NAT for the PC on the PIX (PAT wont work)&lt;/P&gt;&lt;P&gt;2 - open up UDP 500, UDP 1701, and ESP traffic for client NATed address on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Afaq&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 06 Apr 2003 05:52:47 GMT</pubDate>
    <dc:creator>afakhan</dc:creator>
    <dc:date>2003-04-06T05:52:47Z</dc:date>
    <item>
      <title>l2tp/ipsec through a PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-through-a-pix/m-p/134988#M607417</link>
      <description>&lt;P&gt;hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the scenario is this:&lt;/P&gt;&lt;P&gt;I have a user in my network that needs to connect to a VPN server in the Internet, his VPN uses l2tp/ipsec, he uses the windows 2000/XP VPN Client. There is a PIX 535 6.2(2) between the user and his VPN server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem is that this user can't establish a connection with his VPN, he can reach his VPN server, but cannot negotiate a successfull login, the VPN client says: "Remote server timeout" when the user tries to authenticate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The VPN Client Logs a successfull VPN connection as follows:&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;	Operating System      : Windows NT 5.1 Service Pack 1&lt;/P&gt;&lt;P&gt;	Dialer Version        : 7.2.2600.1106&lt;/P&gt;&lt;P&gt;	Connection Name       : ITG Connection Manager for Smart Cards&lt;/P&gt;&lt;P&gt;	All Users/Single User : All Users&lt;/P&gt;&lt;P&gt;	Start Date/Time       : 4/1/2003, 16:43:33&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;	Module Name, Time, Log ID, Log Item Name, Other Info&lt;/P&gt;&lt;P&gt;	For Connection Type, 0=dial-up, 1=VPN, 2=VPN over dial-up&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;[cmdial32]	16:43:33	03	Pre-Init Event	CallingProcess = C:\WINDOWS\System32\CMMON32.EXE&lt;/P&gt;&lt;P&gt;[cmdial32]	16:43:35	04	Pre-Connect Event	ConnectionType = 1&lt;/P&gt;&lt;P&gt;[cmdial32]	16:43:35	09	Custom Action Exe	ActionType = Pre-Connect Actions Description = Security Check before Connecting ActionPath = WSCRIPT.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	16:43:35	06	Pre-Tunnel Event	UserName = &lt;A href="mailto:my_user@northamerica.corp.company.com" target="_blank"&gt;my_user@northamerica.corp.company.com&lt;/A&gt; Domain =  DUNSetting = ITG Connection Manager for Smart Cards Tunnel DeviceName =  TunnelAddress = CXN-REDMOND.COMPANY.COM&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	07	Connect Event&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	09	Custom Action Exe	ActionType = Connect Actions Description = Run additional cred harvesting for NTLM only aware apps ActionPath = WSCRIPT.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	09	Custom Action Exe	ActionType = Connect Actions Description = Security Check after Connecting ActionPath = WSCRIPT.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	09	Custom Action Exe	ActionType = Connect Actions Description = (none) ActionPath = CMDL32.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	08	Custom Action Dll	ActionType = Connect Actions Description = to determine your proxy server ActionPath = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Cm\ITGRASSC\CMSAMPLE.DLL ReturnValue = 0x0&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	08	Custom Action Dll	ActionType = Connect Actions Description = to configure your IE proxy settings ActionPath = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Cm\ITGRASSC\CMPROXY.DLL ReturnValue = 0x0&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	09	Custom Action Exe	ActionType = Connect Actions Description = (none) ActionPath = CMDL32.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	16:44:09	09	Custom Action Exe	ActionType = Connect Actions Description = CM Version Checking ActionPath = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Cm\ITGRASSC\GETCM.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[CMDL32]  	16:44:26	26	Successful Phonebook download	PhoneBookName = mscorppb RequestedPBVer = 73 PBServerUrl = cusredb11rad02&lt;/P&gt;&lt;P&gt;[CMDL32]  	16:44:26	28	Phonebook successfully updated	Type = No update required PhoneBookName = mscorppb OldPBVer = 73 NewPBVer = 73 PBServerUrl = cusredb11rad02&lt;/P&gt;&lt;P&gt;[CMDL32]  	16:44:30	26	Successful Phonebook download	PhoneBookName = Cisco RequestedPBVer = 73 PBServerUrl = cusredb11rad02&lt;/P&gt;&lt;P&gt;[CMDL32]  	16:44:30	28	Phonebook successfully updated	Type = No update required PhoneBookName = Cisco OldPBVer = 73 NewPBVer = 73 PBServerUrl = cusredb11rad02&lt;/P&gt;&lt;P&gt;[CMDL32]  	16:44:36	27	Phonebook download failed	ErrorCode = 204 PhoneBookName = MSROI PBServerUrl = phonebook.attglobal.net&lt;/P&gt;&lt;P&gt;[CMDL32]  	16:44:37	27	Phonebook download failed	ErrorCode = 204 PhoneBookName = MSPPP PBServerUrl = pbkMS.equant.com&lt;/P&gt;&lt;P&gt;[CMDL32]  	16:44:48	27	Phonebook download failed	ErrorCode = 502 PhoneBookName = UUpMSemp PBServerUrl = pbk.uudial.uu.net&lt;/P&gt;&lt;P&gt;[cmdial32]	17:01:15	12	Disconnect Event	CallingProcess = C:\WINDOWS\explorer.exe&lt;/P&gt;&lt;P&gt;[CMMON32] 	17:01:15	22	External Disconnect&lt;/P&gt;&lt;P&gt;[cmdial32]	17:01:15	08	Custom Action Dll	ActionType = Disconnect Actions Description = to restore your previous IE proxy settings ActionPath = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Cm\ITGRASSC\CMPROXY.DLL ReturnValue = 0x0&lt;/P&gt;&lt;P&gt;[cmdial32]	17:01:15	09	Custom Action Exe	ActionType = Disconnect Actions Description = Security Check after Disconnect ActionPath = WSCRIPT.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	17:01:15	09	Custom Action Exe	ActionType = Disconnect Actions Description = Install Updated CM Profile ActionPath = C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Connections\Cm\ITGRASSC\INSTCM.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and the Log when trying to connect behind the PIX:&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;	Operating System      : Windows NT 5.1 Service Pack 1&lt;/P&gt;&lt;P&gt;	Dialer Version        : 7.2.2600.1106&lt;/P&gt;&lt;P&gt;	Connection Name       : ITG Connection Manager for Smart Cards&lt;/P&gt;&lt;P&gt;	All Users/Single User : All Users&lt;/P&gt;&lt;P&gt;	Start Date/Time       : 4/2/2003, 13:15:00&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;	Module Name, Time, Log ID, Log Item Name, Other Info&lt;/P&gt;&lt;P&gt;	For Connection Type, 0=dial-up, 1=VPN, 2=VPN over dial-up&lt;/P&gt;&lt;P&gt;******************************************************************&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:00	03	Pre-Init Event	CallingProcess = C:\WINDOWS\explorer.exe&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:09	04	Pre-Connect Event	ConnectionType = 1&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:09	09	Custom Action Exe	ActionType = Pre-Connect Actions Description = Security Check before Connecting ActionPath = WSCRIPT.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:09	06	Pre-Tunnel Event	UserName = &lt;A href="mailto:my_user@northamerica.corp.company.com" target="_blank"&gt;my_user@northamerica.corp.company.com&lt;/A&gt; Domain =  DUNSetting = ITG Connection Manager for Smart Cards Tunnel DeviceName =  TunnelAddress = CXN-REDMOND.COMPANY.COM&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:37	19	On-Cancel Event&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:46	04	Pre-Connect Event	ConnectionType = 1&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:46	09	Custom Action Exe	ActionType = Pre-Connect Actions Description = Security Check before Connecting ActionPath = WSCRIPT.EXE.  The program was launched successfully.&lt;/P&gt;&lt;P&gt;[cmdial32]	13:15:46	06	Pre-Tunnel Event	UserName = &lt;A href="mailto:my_user@northamerica.corp.company.com" target="_blank"&gt;my_user@northamerica.corp.company.com&lt;/A&gt; Domain =  DUNSetting = ITG Connection Manager for Smart Cards Tunnel DeviceName =  TunnelAddress = CXN-REDMOND.COMPANY.COM&lt;/P&gt;&lt;P&gt;[cmdial32]	13:16:29	20	On-Error Event	ErrorCode = 721 ErrorSource = RAS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no access-lists in my PIX, and I use PAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there an additional configuration that I have to enter in the pix in order to permit this kind of traffic? Is it that I have to use NAT besides PAT? Do I need to permit trafic from the outside interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you in advance &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:40:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-through-a-pix/m-p/134988#M607417</guid>
      <dc:creator>mauro.elias</dc:creator>
      <dc:date>2020-02-21T06:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: l2tp/ipsec through a PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-through-a-pix/m-p/134989#M607418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to make sure that:&lt;/P&gt;&lt;P&gt;1 - you have a static NAT for the PC on the PIX (PAT wont work)&lt;/P&gt;&lt;P&gt;2 - open up UDP 500, UDP 1701, and ESP traffic for client NATed address on the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;Afaq&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 06 Apr 2003 05:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-through-a-pix/m-p/134989#M607418</guid>
      <dc:creator>afakhan</dc:creator>
      <dc:date>2003-04-06T05:52:47Z</dc:date>
    </item>
  </channel>
</rss>

