<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: passing W2K PPTP through PIX 6.0 to external address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78767#M704420</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;doh! I should have kept looking.  A previous post ansered this question for me I think.  PAT is the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any ideas on a work around ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 04 Oct 2001 22:01:26 GMT</pubDate>
    <dc:creator>rtober</dc:creator>
    <dc:date>2001-10-04T22:01:26Z</dc:date>
    <item>
      <title>passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78766#M704419</link>
      <description>&lt;P&gt;I'm trying to establish a W2K pro PPTP tunnel through a PIX out to an external Multi-homed W2K server (across public internet).  When I initiate the client (secure side of PIX) it contacts the external server and begins to authenticate but eventually times out.  I've verified the client PPTP setup using an external dial-out account (bypassing my entire network) and it connects just fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My first guess is the PAT on the firewall is interfering with the W2K PPTP handshake - I know the Cisco Client allows for IPsec though NAT but I couldn't find anything like that in the W2K setup ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:51:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78766#M704419</guid>
      <dc:creator>rtober</dc:creator>
      <dc:date>2020-02-21T05:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78767#M704420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;doh! I should have kept looking.  A previous post ansered this question for me I think.  PAT is the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you have any ideas on a work around ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Oct 2001 22:01:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78767#M704420</guid>
      <dc:creator>rtober</dc:creator>
      <dc:date>2001-10-04T22:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78768#M704421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What was the solution for your problem.  I'm having the same issue &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2001 16:35:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78768#M704421</guid>
      <dc:creator>pag</dc:creator>
      <dc:date>2001-10-08T16:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78769#M704422</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to set up a conduit or access list through the firewall with a static ip address to the internal computer. The internal computer can send packets out, but the packets are blocked at the firewall from getting back in. I was told to open up ports for PPTP,(I can't remember what they were) but that didn't work. I ended up allowing TCP from host to host(from the IP address of the PC outside your network to the external(public) ip of the computer inside your network. I hope this helps, if you need more help I can post some configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jp&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2001 17:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78769#M704422</guid>
      <dc:creator>jpoulos</dc:creator>
      <dc:date>2001-10-08T17:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78770#M704423</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried allowing pptp access, with no luck, and would realy like to see your configs. What i have done: Created static 1-to-1 Nat translation, opened tcp eq 1723 &amp;amp; protocol 47 (gre) outbound and inbound.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 12.x.x.x 10.x.x.x netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;access-list allow_outbound permit gre 10.0.0.0 255.0.0.0 any &lt;/P&gt;&lt;P&gt;access-list allow_outbound permit tcp 10.0.0.0 255.255.0.0 any eq 1723&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list allow_inbound permit ip any host 12.x.x.x&lt;/P&gt;&lt;P&gt;access-list allow_inbound permit gre any host 12.x.x.x&lt;/P&gt;&lt;P&gt;access-list allow_inbound permit tcp any host 12.x.x.x eq 1723&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition, i allowed ALL outbound &amp;amp; ALL inbound to and from any with NO luck (just for testing).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Oct 2001 21:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78770#M704423</guid>
      <dc:creator>mconroy</dc:creator>
      <dc:date>2001-10-09T21:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78771#M704424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;jp,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought the PIX had implicit permit all for outbound connections initiated from the inside (secure leg) and automatically allowed the reply to pass back through as long as the reply packet was good.  Implicit deny all is only applied to connections initiated from the outside in right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have to open up return ports for outbound http traffic, etc ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wondering ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2001 16:59:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78771#M704424</guid>
      <dc:creator>rtober</dc:creator>
      <dc:date>2001-10-18T16:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78772#M704425</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well right now I'm going to forget the internal client configuration because I don't want to short-circuit our DMZ and bring a direct connection straight through.  I'm going to try a Lan-to-lan connection using our 3030.  I've initiated lan-to-lan with 2 PIXs using IPsec but never with PPTP to a W2K server.  Should be tons-O-fun.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2001 17:04:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78772#M704425</guid>
      <dc:creator>rtober</dc:creator>
      <dc:date>2001-10-18T17:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78773#M704426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are two ways you can do it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The first way allows for a point to point access from a specific host to a specific host. The second way allows for VPN PPTP connections to anywhere and back, but it is a little less secure. It looks like the only difference between our configs is you don't have the permit UDP statement. Let me know if you have any questions.( the 216 in my config is the external host that we are connecting to)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 237.xx.xx.1 10.xx.xx.1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-list REMOTE permit ip host 216.xx.xx.xx host 237.xx.xx.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 237.xx.xx.2 10.xx.xx.2 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;access-list REMOTE permit ip any host 237.xx.xx.2&lt;/P&gt;&lt;P&gt;access-list REMOTE permit udp any host 237.xx.xx.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2001 19:45:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78773#M704426</guid>
      <dc:creator>jpoulos</dc:creator>
      <dc:date>2001-10-18T19:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: passing W2K PPTP through PIX 6.0 to external address</title>
      <link>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78774#M704427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try a debug packet on outside (specify W2K  server as source in order to filter the traffic) in order to see what arrives on PIX port and why it's discarded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maurizio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2001 12:42:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/passing-w2k-pptp-through-pix-6-0-to-external-address/m-p/78774#M704427</guid>
      <dc:creator>murriware</dc:creator>
      <dc:date>2001-10-19T12:42:41Z</dc:date>
    </item>
  </channel>
</rss>

