09-18-2003 08:24 AM - edited 03-09-2019 04:51 AM
I am having an issue with a Cisco 3000 VPN server. Multiple clients at one location need to connect back to the VPN server via PPTP. The location is served by a DSL line with a basic NAT router. The first client is able to connect and the rest are rejected. I am assuming this is a "security feature" of the 3000 box. My guess is that the 3000 likes an individual IP address for each session. Has anyone seen this problem?
John
09-18-2003 04:48 PM
Hi,
PPTP thru PAT is not supported.
Thanks
Ranjana
09-19-2003 03:35 AM
Hi Ranjana,
Why is it so that PPTP is not supported thru PAT. I understand that ipsec is not supported coz of esp not using ports...but how the same applies to pptp as it uses pptp for tunneling and mppe for encryption
Thanks
Atul.
09-19-2003 10:51 AM
Hi Atul,
PPTP uses GRE, so the NAT/PAT device should be capable of handling GRE/PAT.
Thanks
Ranjana
09-19-2003 07:44 AM
This is very disappointing. Because now I must go back to using RRAS on Win2k. Cisco should add this feature to the 3000 VPN box.
09-19-2003 10:33 AM
Hi,
I missed adding in my previous message that it appears that your router doesn't support GRE/PAT. The Concentrator supports PPTP through PAT as long as your NAT/PAT device supports GRE/PAT
Thanks
Ranjana
10-16-2003 10:50 AM
The VPN 3000 series will only allow a single connection from a particular IP address. Snapgear makes a $300 router that will build the PPTP connection to the Cisco 3000 box and then multiple clients can go through that tunnel. The individual client machines do not create a tunnel or authenticate in this scenario. It's a nailed-up point-to-point connection connecting two lans. I have one engineer using this from home quite successfully.
Tom Zeller
Indiana University
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide