<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 not allowing PPTP traffic from inside device to ext in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174733#M877208</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you should do that, do you recognize this ip address 216.13.201.234? is that the server's ip address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 26 Jan 2009 21:00:39 GMT</pubDate>
    <dc:creator>Ivan Martinon</dc:creator>
    <dc:date>2009-01-26T21:00:39Z</dc:date>
    <item>
      <title>ASA 5510 not allowing PPTP traffic from inside device to external server</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174728#M877201</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I've tried everything to get this to work with no joy. I'm hoping someone out here can help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Essentially we have inside clients running XP and Vista using the PPTP client to connect to a VPN server outside. The connections always fail (but are successful from other networks).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The log entries are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4	Jan 26 2009	11:41:40	713903			 IP = 216.13.201.234, Information Exchange processing failed&lt;/P&gt;&lt;P&gt;5	Jan 26 2009	11:41:40	713904			 IP = 216.13.201.234, Received an un-encrypted NO_PROPOSAL_CHOSEN notify message, dropping&lt;/P&gt;&lt;P&gt;3	Jan 26 2009	11:41:40	106100	192.168.111.66	216.13.201.234	 access-list Inside_access_in permitted tcp Inside/192.168.111.66(1375) -&amp;gt; Outside/216.13.201.234(1723) hit-cnt 1 first hit [0x7001adbb, 0xeac55bde]&lt;/P&gt;&lt;P&gt;4	Jan 26 2009	11:39:24	713903			 IP = 216.13.201.234, Error: Unable to remove PeerTblEntry&lt;/P&gt;&lt;P&gt;3	Jan 26 2009	11:39:24	713902			 IP = 216.13.201.234, Removing peer from peer table failed, no match!&lt;/P&gt;&lt;P&gt;4	Jan 26 2009	11:38:52	713903			 IP = 216.13.201.234, Information Exchange processing failed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please see the attached running config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks guys!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 00:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174728#M877201</guid>
      <dc:creator>graham.fleming</dc:creator>
      <dc:date>2019-03-26T00:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174729#M877203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By other networks, you mean other networks behind the ASA or other networks outside the ASA? Go ahead and increase the log on your ASA since it does not show that there is something wrong on the specific log.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 20:47:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174729#M877203</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-26T20:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174730#M877205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By other networks I mean other networks not behind the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that log output is showing all log messages up to level 7. Are you sure those messages on the log output aren't problematic?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 20:48:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174730#M877205</guid>
      <dc:creator>graham.fleming</dc:creator>
      <dc:date>2009-01-26T20:48:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174731#M877206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only log that shows reference to a PPTP connection is the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3 Jan 26 2009 11:41:40 106100 192.168.111.66 216.13.201.234 access-list Inside_access_in permitted tcp Inside/192.168.111.66(1375) -&amp;gt; Outside/216.13.201.234(1723) hit-cnt 1 first hit [0x7001adbb, 0xeac55bde] &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The rest of the lines are related to a vpn connection not being established.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 20:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174731#M877206</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-26T20:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174732#M877207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Those messages all appear with the connection attempt, though. They aren't a separate issue. Everytime the client tries to connect, those 5 messages appear in the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I try turning off PPTP inspection maybe?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 20:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174732#M877207</guid>
      <dc:creator>graham.fleming</dc:creator>
      <dc:date>2009-01-26T20:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174733#M877208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think you should do that, do you recognize this ip address 216.13.201.234? is that the server's ip address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 21:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174733#M877208</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-26T21:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174734#M877209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that's the server IP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 21:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174734#M877209</guid>
      <dc:creator>graham.fleming</dc:creator>
      <dc:date>2009-01-26T21:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174735#M877210</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Odd..Does this happen to all the clients that try this connection behind this ASA? It seems as if the ASA was intercepting this connection and using it for itself, can you try again this connection and while doing this go ahea and get the "show conn &lt;CLIENT ip=""&gt;" and "show local-host &lt;CLIENT ip=""&gt;" when this occur?&lt;/CLIENT&gt;&lt;/CLIENT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client ip is the workstation ip address you are trying from.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If possible go ahead and remove the Crypto map from outside interface while trying this too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 21:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174735#M877210</guid>
      <dc:creator>Ivan Martinon</dc:creator>
      <dc:date>2009-01-26T21:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174736#M877211</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I think is happening is you have the following config for Nat cntrl &lt;/P&gt;&lt;P&gt;global (Outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (Inside) 0 access-list Inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (Inside) 1 access-list Inside_nat_outbound&lt;/P&gt;&lt;P&gt;nat (management) 101 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and with this statement &lt;/P&gt;&lt;P&gt;access-list Outside_access_in extended permit tcp any host access-list Outside_access_in extended permit tcp any host 216.13.201.234 eq pptp &lt;/P&gt;&lt;P&gt;basically permits any outside (src) traffic &lt;PPTP&gt; to access the dst 216.13.201.234, but then your static &lt;/PPTP&gt;&lt;/P&gt;&lt;P&gt;static (Inside,Outside) tcp interface pptp 192.168.111.224 pptp netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;is using the interface as outside address to 192.168.111.224, and the rproblem is that the interface ip address is noy in the same subnet as your destination address &lt;/P&gt;&lt;P&gt;Interface address = 216.13.219.142 255.255.255.248 while your acl dst is 216.13.201.234.HTH&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 21:14:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174736#M877211</guid>
      <dc:creator>sdoremus33</dc:creator>
      <dc:date>2009-01-26T21:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174737#M877212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for this info. Wouldn't &lt;/P&gt;&lt;P&gt;static (Inside,Outside) tcp interface pptp 192.168.111.224 pptp netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;be used for incoming PPTP connections to .224?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are concerned with outgoing connections here to external PPTP servers. I removed that static NAT with no change.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jan 2009 22:04:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174737#M877212</guid>
      <dc:creator>graham.fleming</dc:creator>
      <dc:date>2009-01-26T22:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 not allowing PPTP traffic from inside device to ext</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174738#M877213</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My apologies, I misread the post and thought this issue was with incoming connections to .224&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jan 2009 03:30:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-not-allowing-pptp-traffic-from-inside-device-to/m-p/1174738#M877213</guid>
      <dc:creator>sdoremus33</dc:creator>
      <dc:date>2009-01-27T03:30:07Z</dc:date>
    </item>
  </channel>
</rss>

