<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic vpn issues with windows based vpn in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915260#M959702</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to connect to my office from home through a windows based VPN (win 2003 and win XP) and have issues with it. I have a PIX 506E firewall in the office and there is no firewall at home.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone advise what other configuration is needed on the pix firewall to achieve this. I have opened ports 1723, 500 on pix firewall for external access and configured office pix as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 102 permit ip 10.10.10.0 255.255.255.0 192.168.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip local pool vpn-clients 192.168.1.1-192.168.1.50&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 102&lt;/P&gt;&lt;P&gt;sysopt connection permit-pptp&lt;/P&gt;&lt;P&gt;vpdn group 1 accept dialin pptp&lt;/P&gt;&lt;P&gt;vpdn group 1 ppp authentication pap&lt;/P&gt;&lt;P&gt;vpdn group 1 ppp authentication chap&lt;/P&gt;&lt;P&gt;vpdn group 1 ppp authentication mschap&lt;/P&gt;&lt;P&gt;vpdn group 1 client configuration address local vpn-clients&lt;/P&gt;&lt;P&gt;vpdn group 1 client authentication local&lt;/P&gt;&lt;P&gt;vpdn enable outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be authenticating with my domain username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my network - 172.16.x.x&lt;/P&gt;&lt;P&gt;office network - 10.10.10.x&lt;/P&gt;&lt;P&gt;vpn client network assigned on pix - 192.168.1.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your early response is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you&lt;/P&gt;&lt;P&gt;venkat&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 11:37:10 GMT</pubDate>
    <dc:creator>sarat1317</dc:creator>
    <dc:date>2019-03-11T11:37:10Z</dc:date>
    <item>
      <title>vpn issues with windows based vpn</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915260#M959702</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to connect to my office from home through a windows based VPN (win 2003 and win XP) and have issues with it. I have a PIX 506E firewall in the office and there is no firewall at home.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone advise what other configuration is needed on the pix firewall to achieve this. I have opened ports 1723, 500 on pix firewall for external access and configured office pix as below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list 102 permit ip 10.10.10.0 255.255.255.0 192.168.1.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;ip local pool vpn-clients 192.168.1.1-192.168.1.50&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list 102&lt;/P&gt;&lt;P&gt;sysopt connection permit-pptp&lt;/P&gt;&lt;P&gt;vpdn group 1 accept dialin pptp&lt;/P&gt;&lt;P&gt;vpdn group 1 ppp authentication pap&lt;/P&gt;&lt;P&gt;vpdn group 1 ppp authentication chap&lt;/P&gt;&lt;P&gt;vpdn group 1 ppp authentication mschap&lt;/P&gt;&lt;P&gt;vpdn group 1 client configuration address local vpn-clients&lt;/P&gt;&lt;P&gt;vpdn group 1 client authentication local&lt;/P&gt;&lt;P&gt;vpdn enable outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be authenticating with my domain username and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my network - 172.16.x.x&lt;/P&gt;&lt;P&gt;office network - 10.10.10.x&lt;/P&gt;&lt;P&gt;vpn client network assigned on pix - 192.168.1.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your early response is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you&lt;/P&gt;&lt;P&gt;venkat&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:37:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915260#M959702</guid>
      <dc:creator>sarat1317</dc:creator>
      <dc:date>2019-03-11T11:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issues with windows based vpn</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915261#M959703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Venkat&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You state you wish to use some sort of AAA authentication in order to authenticate against your domain credentials, but you have configured the VPN to use local client authentication without supplying it with a username and password, such as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpdn username cisco password cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following link should get you started with enabling AAA for PPTP VPN:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080143a5d.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080143a5d.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kev&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2007 09:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915261#M959703</guid>
      <dc:creator>kagodfrey</dc:creator>
      <dc:date>2007-11-30T09:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issues with windows based vpn</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915262#M959704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kev&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response. I guess I am making a mistake here. Actually I am just using my domain name and password to get authenticated which is through the Win 2003 SBS server. So I dont think I need &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpdn group 1 client authentication local &lt;/P&gt;&lt;P&gt;vpdn username cisco password cisco&lt;/P&gt;&lt;P&gt;(But again I tried this as well and didnt work)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But do I have to use any command for windows based authentication?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have created a VPN connection and on properties, I have tabs as below&lt;/P&gt;&lt;P&gt;General - public IP of office Internet&lt;/P&gt;&lt;P&gt;Options - all are checked on dialing options&lt;/P&gt;&lt;P&gt;(display progress, prompt for name &amp;amp; pwd, include windows logon domain)&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Security - typical&lt;/P&gt;&lt;P&gt;required secured password under validate my identity&lt;/P&gt;&lt;P&gt;automatically use my windows logon name, pwd - unchecked&lt;/P&gt;&lt;P&gt;require data encryption - unchecked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;networking - PPTP VPN (type of VPN)&lt;/P&gt;&lt;P&gt;Advanced - win firewall is off&lt;/P&gt;&lt;P&gt;internet connection sharing - unchecked&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2007 15:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915262#M959704</guid>
      <dc:creator>sarat1317</dc:creator>
      <dc:date>2007-11-30T15:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issues with windows based vpn</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915263#M959705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having re-read your original post, I have a few further thoughts as to why it will not work.  You do not need to open 1723 and 500 on the pix, your vpdn configuration allows pptp to bypass conduit/acl checks when it is enabled (the sysopt connection permit-pptp command).  However, I think you do need to ensure you have permitted 1723 outbound (likely) and GRE (protocol 47) inbound (unlikely), and that you are using a 1-to-1 static NAT translation between your inside private address on your 172.16.0.0 network and (one of) your public address on your outside block.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you only have PAT and are not able to configure a static NAT entry then I don't think it will work.  The alternative would be to configure an NAT-T aware IPSEC VPN tunnel to the Pix using the Cisco VPN Client, which will happily work with PAT - details of how to configure this can be found here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a008009442e.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a008009442e.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and nat-t here:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/ipsecint.html#wp1057446" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/pix/pix63/configuration/guide/ipsecint.html#wp1057446&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kev&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2007 17:12:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915263#M959705</guid>
      <dc:creator>kagodfrey</dc:creator>
      <dc:date>2007-11-30T17:12:06Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issues with windows based vpn</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915264#M959706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kev&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did not expect that this is so critical or may be just critical for me. I have attached the config here. It worked pretty well when Linksys router was in place and just these issues after replacing with PIX. Unfortunately I dont have much time and I may have to revert back if this doesnt work in next few hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure if I am doing some basic mistakes here about the user authentication etc. When I enable logging, I am getting this message. PPTP: Call id 32975, no session&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please check the config and advise. I am looking at other solutions now. Right now I am not using any Cisco VPN client. I guess these are not free right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all your time&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2007 17:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915264#M959706</guid>
      <dc:creator>sarat1317</dc:creator>
      <dc:date>2007-11-30T17:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: vpn issues with windows based vpn</title>
      <link>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915265#M959707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kev&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have removed the static translations for PPTP and authentication is done locally by PIX and that worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time and help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2007 19:47:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/vpn-issues-with-windows-based-vpn/m-p/915265#M959707</guid>
      <dc:creator>sarat1317</dc:creator>
      <dc:date>2007-11-30T19:47:49Z</dc:date>
    </item>
  </channel>
</rss>

