cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 
cancel
2213
Views
0
Helpful
3
Replies

Microsoft VPN client and GRE

bapatsubodh
Level 1
Level 1

Hello,

Trying to access Microsoft VPN (on the internet-outside zone) server from  Microsoft VPN client (inside zone)

On ASA - allowed all outbound traffic from inside to outside-internet and all traffic is blocked from internet-outside to internet.

VPN client seems to be not working in this case. When firewall was bypased Microsoft VPN client got connected to Remote Microsoft VPN server.

Do we need to enable GRE from outside to inside for this work? ( along with corresponding static NAT entry for the remote Microsoft VPN server)

Microsoft tech support document did mention about permitting GRE through firewall but it's not stating any direction.

Please share the experience.


Thanks in advance

Subodh

1 Accepted Solution

Accepted Solutions

Yes, once the inspection is enabled for PPTP, ASA will automatically open hole for GRE as per stated in the documentation advised earlier.

View solution in original post

3 Replies 3

Jennifer Halim
Cisco Employee
Cisco Employee

Please enable "inspect pptp" that would allow the GRE connection.

Here is the command for your reference:

http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/i2.html#wp1741718

Thanks for the link.

So when we enable the inspection for PPTP (similar to other protocols those are already configured for inspection) will the ASA permit the GRE traffic to cross from outside to inside?

As wireshark-packetcapture shows first GRE packet coming from the Microsoft VPN server to the client indicating that ------- "Server is initiating the GRE connection".

Please advice.

Thanks in advance.

Cheers!

S.

Yes, once the inspection is enabled for PPTP, ASA will automatically open hole for GRE as per stated in the documentation advised earlier.

Review Cisco Networking products for a $25 gift card