11-29-2020 11:13 PM - edited 11-29-2020 11:38 PM
Hi there,
Dear Technical team, i have configured vpn on windows server 2019, and i have created a access rule for specific ports in cisco asa, but whenever i am trying to connect to the vpn its giving me error and i am not able to login to the vpn dialup connection. the error i am getting is attached, please do check it and help me...
i have created the access rule as well in firewall which is given below
12-02-2020 04:02 AM - edited 12-02-2020 12:05 PM
...
12-02-2020 07:53 AM
@MHM Cisco Worldas i know shouldnt it be the machine IP on which VPN is configured, i mean if i put it here the outside interface then where my request will go ?
12-02-2020 08:15 AM - edited 12-02-2020 12:05 PM
....
12-02-2020 01:08 PM
sorry for late reply BUT ASDM is so hard to explain than CLI, this is why some mistake and other not reply soon.
So friend we will take Step by Step
1- ACL with GRE
2-ACL with TCP pptp
3- inspect PPTP
12-02-2020 08:15 PM - edited 12-02-2020 08:23 PM
@MHM Cisco Worldi am really sorry i am disturbing you again n again,
let me configure these settings, then i will let you know,
but apart from all that i am just copying these things, i am not able to understand why we are not using machine ip address in destination in ACL on which vpn is configured
12-02-2020 01:11 PM
Part 2
config the Port Forward for TCP PPTP here the issue I think after I make double Look
NOW instead of real port http we will select PPTP.
try this config
and Hope this help you.
12-02-2020 08:33 PM
i have created these ACL Rules for GRE and PPTP, after saving the settings, internet stopped working on client machines, i dont know why, so i had to revert back delete these ACL rules to make internet work, i dont know why its happening and for what reasons
12-03-2020 04:28 AM - edited 12-03-2020 04:35 AM
Ok, first after apply acl the vpn client success connect to server?
Tcp/ip setting on windows vpn, unclick the default gateway through vpn.
this make only local traffic pass through vpn and internet go through your internet’s connection.
check this point please
12-03-2020 07:10 AM
@MHM Cisco Worldsorry i didnt get your point i am so dumb, what exactly you are asking can you explain me a bit please.
i have created ACL and applied these settings, after i saved these settings, internet access on client machines stopped working. i didnt try to connect vpn because internet stopped working. this is why i had to delete these rules without even checking to connect the vpn.
12-03-2020 10:46 AM
If PPTP client is filled to connect to internet after config VPN try above.
12-03-2020 08:05 PM
@MHM Cisco Worldthis settings have to be done on the machine from where i am going to connect the VPN right ? or on the server where PPTP VPN is configured ? ...
12-04-2020 08:10 AM
on VPN client not server
12-04-2020 11:37 AM
yeah but i told you when i am creating the ACL rules then internet stop working on the clients which are using laptop and workgroup in my office through ASA, so i deleted these rules, because it seems like i am doing something wrong, but i have followed the steps you told me exactly, in short i copied them as it is. but internet stopped working so i deleted these rules.
and i am connecting the vpn not from the office client, i am connecting the vpn through any other random computer or from my home laptop so does it really make any difference if i change these lan card settings ? because when the main rules in asa are not configured properly then how a client will be able to connect to server with vpn through asa
i am sorry i know im such a pain in a-- but i am also feeling really annoyed and confused, i am running after one thing from almost over more then 10 days and i am not able to figure it our, though everyone is helping me here and i really appreciated that your efforts
12-02-2020 03:05 PM
for use the real IP or mapped IP this according to ASA versions
ASA before 8.2 use mapped
ASA after 8.3 use real
So you are right.
12-04-2020 11:41 AM
Both Sides use ipv4?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide