cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4453
Views
15
Helpful
32
Replies

VPN Connection

Cash2106
Level 1
Level 1

Hi there,

Dear Technical team, i have configured vpn on windows server 2019, and i have created a access rule for specific ports in cisco asa, but whenever i am trying to connect to the vpn its giving me error and i am not able to login to the vpn dialup connection. the error i am getting is attached, please do check it and help me...

 

i have created the access rule as well in firewall which is given below access.jpg

32 Replies 32

...

@MHM Cisco Worldas i know shouldnt it be the machine IP on which VPN is configured, i mean if i put it here the outside interface then where my request will go ?

....

sorry for late reply BUT ASDM is so hard to explain than CLI, this is why some mistake and other not reply soon.
So friend we will take Step by Step
1- ACL with GRE
00001s.png
2-ACL with TCP pptp
00002s.png00003s.png
3- inspect PPTP
00004s.png

@MHM Cisco Worldi am really sorry i am disturbing you again n again,

 

let me configure these settings, then i will let you know,

but apart from all that i am just copying these things, i am not able to understand why we are not using machine ip address in destination in ACL on which vpn is configured

Part 2
config the Port Forward for TCP PPTP here the issue I think after I make double Look
001-ASA-Add-NAT-Rule-for-Port-Forward.png002-ASA-Add-NAT-Rule-and-host-for-Port-Forward.png
NOW instead of real port http we will select PPTP.
try this config
and Hope this help you.

@MHM Cisco World 

 

i have created these ACL Rules for GRE and PPTP, after saving the settings, internet stopped working on client machines, i dont know why, so i had to revert back delete these ACL rules to make internet work, i dont know why its happening and for what reasons

Ok, first after apply acl the vpn client success connect to server?

Tcp/ip setting on windows vpn, unclick the default gateway through vpn.

this make only local traffic pass through vpn and internet go through your internet’s connection.

check this point please 

@MHM Cisco Worldsorry i didnt get your point i am so dumb, what exactly you are asking can you explain me a bit please.

 

i have created ACL and applied these settings, after i saved these settings, internet access on client machines stopped working. i didnt try to connect vpn because internet stopped working. this is why i had to delete these rules without even checking to connect the vpn.

win7-vpn11_thumb.pngwin7-vpn12_thumb.png

If PPTP client is filled to connect to internet after config VPN try above.

@MHM Cisco Worldthis settings have to be done on the machine from where i am going to connect the VPN right ? or on the server where PPTP VPN is configured ? ...

on VPN client not server 

yeah but i told you when i am creating the ACL rules then internet stop working on the clients which are using laptop and workgroup in my office through ASA, so i deleted these rules, because it seems like i am doing something wrong, but i have followed the steps you told me exactly, in short i copied them as it is. but internet stopped working so i deleted these rules.

 

and i am connecting the vpn not from the office client, i am connecting the vpn through any other random computer or from my home laptop so does it really make any difference if i change these lan card settings ? because when the main rules in asa are not configured properly then how a client will be able to connect to server with vpn through asa

 

i am sorry i know im such a pain in a-- but i am also feeling really annoyed and confused, i am running after one thing from almost over more then 10 days and i am not able to figure it our, though everyone is helping me here and i really appreciated that your efforts

for use the real IP or mapped IP this according to ASA versions 
ASA before 8.2 use mapped 
ASA after 8.3 use real 
So you are right.

Shervin SoAb
Level 1
Level 1

Both Sides use ipv4?

Review Cisco Networking for a $25 gift card