cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1201
Views
0
Helpful
1
Replies

Allowing VPN3000 to x-authenticate NT users across a Pix

m.laporta
Level 1
Level 1

Hi Experts.

I have the following scenario:

NT Server

|

|

(in)

[PIX](dmz)---(in)[VPN3000](out)

(out)

_|______________________|__

Internet

(Both the Pix and the VPN3000 have the outside interface connected to the Internet).

Well, I need to allow the VPN3000 to x-autenticate users using the NT database.

Could someone please tell me what are the protocols/port to open on the Pix?

Thanks

michele

1 Reply 1

scoclayton
Level 7
Level 7

Michele,

Good question. Unfortunately, I have no idea. I would assume that it would be the usual MS suspects (TCP/UDP 135-139) but that is just a guess. My suggestion would be to turn syslogging to debug level and try an authentication from the 3K. Then look at the logs and see what the PIX denied. Sorry I can't be of more help.

Scott