<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: L2TP/IPSec VPN access through PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384105#M730608</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;Hello, i make tests doing all that you said, remove the PAT configuration, asign a new IP to the NAT, but the result is the same; i atach the logs with the info tath receive from the PIX.&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;Regards.&lt;BR /&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 16 Feb 2010 20:00:44 GMT</pubDate>
    <dc:creator>pedrosuero</dc:creator>
    <dc:date>2010-02-16T20:00:44Z</dc:date>
    <item>
      <title>L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384097#M730466</link>
      <description>&lt;P&gt;Hello, i having problem with VPN connection from a windows PC using L2TP/IPsec, i alow all necesary protocols (GRE, ESP, PPTP, UDP-500, UDP-4500 and UDP-1701) on outside interface on PIX (version 8.0(4)), i'm perfectly connect with PPTP but when i tried with L2TP the conecction can't be established, in PIX log i can see the creating session for ports 500 and 4500, on PC have and error that the server can be reach. I'm using a ISA Server cluster for VPN Server, the configuration are like follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC &amp;lt;----&amp;gt; PIX &amp;lt;-----&amp;gt; MS ISA &amp;lt;------&amp;gt; LAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC IP 10.3.0.12/28&lt;/P&gt;&lt;P&gt;PIX external IP 10.3.0.1/28&lt;/P&gt;&lt;P&gt;PIX Internal IP 172.16.0.1/28&lt;/P&gt;&lt;P&gt;ISA external IP 172.16.0.2/28&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm using Static NAT for the external interface of the ISA for the VPN access with IP 10.3.0.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="short_text" id="result_box"&gt;&lt;SPAN onmouseout="" onmouseover="" style="background-color: #ffffff;" title="que podria estar olvidando"&gt;What might be forgetting???&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will appretiated the help any one can provide me.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:08:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384097#M730466</guid>
      <dc:creator>pedrosuero</dc:creator>
      <dc:date>2019-03-11T17:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384098#M730490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pedro&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The details given looks good.. would you have the configs handy ? Just wanted to check the CLI commands that you had used ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to test, were you able to create L2TP session from inside the PIX, just to make sure the server works good ? Do you see any drops on the "show log" of PIX when you initiate L2TP from outside ? sysopt commands can be useful, but thats more for traffic initiating from inside to outside.. in your case its from internet to inside right&amp;nbsp; ? Just curious, do you have any personal firewalls on your desktop ? You can also try opening ip any on the outside and test, just to test if the NAT and other stuff works good... are there any ACLs on the inside?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &amp;amp; Regards&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Feb 2010 22:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384098#M730490</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2010-02-12T22:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384099#M730508</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How about opening TCP/1723? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 14 Feb 2010 05:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384099#M730508</guid>
      <dc:creator>cmcbride</dc:creator>
      <dc:date>2010-02-14T05:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384100#M730524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for response Raj,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attached the config of PIX, in this config you can see that I’m use tree interfaces, one for management with security 100, one DMZ between PIX and MS ISA with security 90 and the Outside with security 0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Answering your questions, I make tests of L2TP sessions from DMZ Sub-net (Attaching PC to this Subnet) to the MS ISA Server and works perfectly, i can't see any drop packets on PIX log when initiated L2TP session from outside, like you said the traffic are initiated from outside, but to DMZ; i turn off the Windows Firewall and the Antivirus Firewall and the result is the same, i make a test open all traffic from outside (IP, TCP, UDP, ICMP) but can connect anyway; I don't have any ACL applied to inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for my English&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Feb 2010 21:25:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384100#M730524</guid>
      <dc:creator>pedrosuero</dc:creator>
      <dc:date>2010-02-15T21:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384101#M730547</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-qformat:yes;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:"Times New Roman";
	mso-fareast-theme-font:minor-fareast;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hello, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;thanks for reply, i already have allowed, can connect PPTP but NOT L2TP&lt;BR /&gt;&lt;BR /&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Feb 2010 21:28:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384101#M730547</guid>
      <dc:creator>pedrosuero</dc:creator>
      <dc:date>2010-02-15T21:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384102#M730569</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In the outside ACL is open for pptp traffic destined to 10.3.0.3.&lt;/P&gt;&lt;P&gt;Shouldn't this guy be translated (currently there is no static translation for it) and someone would be reaching him with its outside ip?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Feb 2010 21:32:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384102#M730569</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-02-15T21:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384103#M730588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, thanks for answer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IP 10.3.0.3 is an static translation from 172.16.0.2, all traffic iniciated to 10.3.0.3 will be destinated to 172.16.0.2 that is the IP of the MS ISA Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Feb 2010 23:17:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384103#M730588</guid>
      <dc:creator>pedrosuero</dc:creator>
      <dc:date>2010-02-15T23:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384104#M730599</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would consider removing the PAT configuration for the ISA server.&amp;nbsp; It may be conflicting with the Static NAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (Outside) 1 10.3.0.3 netmask 255.225.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try using a different IP number for that rather than 10.3.0.3.&amp;nbsp; Allow the static nat to be the only thing using that IP number.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Feb 2010 23:30:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384104#M730599</guid>
      <dc:creator>cmcbride</dc:creator>
      <dc:date>2010-02-15T23:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: L2TP/IPSec VPN access through PIX</title>
      <link>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384105#M730608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV class="jive-rendered-content"&gt;Hello, i make tests doing all that you said, remove the PAT configuration, asign a new IP to the NAT, but the result is the same; i atach the logs with the info tath receive from the PIX.&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;&lt;BR /&gt;&lt;/DIV&gt;&lt;DIV class="jive-rendered-content"&gt;Regards.&lt;BR /&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Feb 2010 20:00:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2tp-ipsec-vpn-access-through-pix/m-p/1384105#M730608</guid>
      <dc:creator>pedrosuero</dc:creator>
      <dc:date>2010-02-16T20:00:44Z</dc:date>
    </item>
  </channel>
</rss>

