Issue with Cisco Pix 501, and MS VPN connecting to Cisco 3005 VPN? Multiple connections

Issue with Cisco Pix 501, and MS VPN connecting to Cisco 3005 VPN? Multiple connections

NewsGroups | Search | Tools
 alt.certification.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Issue with Cisco Pix 501, and MS VPN connecting to Cisco 3005 VPN? Multiple connections rhalljr 02-11-2008
Posted by rhalljr on February 11, 2008, 10:03 am
If you were  Registered and logged in, you could reply and use other advanced thread options
We are setting up a temporary satellite office about 15 minutes away,
and we are running into a minor problem with the client connectivity
from that office.

Ill explain the hardware real quick. In our main office, we have a PIX
506e Firewall, with the 3005 Concentrator behind it for VPN. We are
using the MS client via PPTP to connect for VPN.

In the satellite office, we simply have a Pix 501, with 6-8 client
desktops behind it. We will need all of them to be able to connect to
the Cisco VPN using the MS Windows VPN connection.

Is there something i need to do to make this happen? Right now it
appears that one 1 of them at a time can connect.

Thanks in advance.... I am not a cisco certified guy yet, but i plan on
working towards it someday soon.

Rodney

Pure Networks
Posted by Yandy Ramirez on February 11, 2008, 10:26 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Yes for windows PPTP clients you need to inspect PPTP at the PIX level.
We ran into an issue like that.

Versions <= 6.3

Fixup protocol pptp 1723

Also allow GRE on your access lists.

Version >= 7.0

pixfirewall(config)#policy-map global_policy

pixfirewall(config-pmap)#class inspection_default

pixfirewall(config-pmap-c)#inspect pptp


Hope that helps.

You may also need to allow GRE through.


On 2/11/08 10:03 AM, in article 47b063be$0$8649$4c368faf@roadrunner.com,

> We are setting up a temporary satellite office about 15 minutes away,
> and we are running into a minor problem with the client connectivity
> from that office.
>
> Ill explain the hardware real quick. In our main office, we have a PIX
> 506e Firewall, with the 3005 Concentrator behind it for VPN. We are
> using the MS client via PPTP to connect for VPN.
>
> In the satellite office, we simply have a Pix 501, with 6-8 client
> desktops behind it. We will need all of them to be able to connect to
> the Cisco VPN using the MS Windows VPN connection.
>
> Is there something i need to do to make this happen? Right now it
> appears that one 1 of them at a time can connect.
>
> Thanks in advance.... I am not a cisco certified guy yet, but i plan on
> working towards it someday soon.
>
> Rodney


Posted by rhalljr on February 11, 2008, 10:48 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Yandy Ramirez wrote:
> Yes for windows PPTP clients you need to inspect PPTP at the PIX level.
> We ran into an issue like that.
>
> Versions <= 6.3
>
> Fixup protocol pptp 1723
>
> Also allow GRE on your access lists.
>
> Version >= 7.0
>
> pixfirewall(config)#policy-map global_policy
>
> pixfirewall(config-pmap)#class inspection_default
>
> pixfirewall(config-pmap-c)#inspect pptp
>
>
> Hope that helps.
>
> You may also need to allow GRE through.
>
>
> On 2/11/08 10:03 AM, in article 47b063be$0$8649$4c368faf@roadrunner.com,
>
>> We are setting up a temporary satellite office about 15 minutes away,
>> and we are running into a minor problem with the client connectivity
>> from that office.
>>
>> Ill explain the hardware real quick. In our main office, we have a PIX
>> 506e Firewall, with the 3005 Concentrator behind it for VPN. We are
>> using the MS client via PPTP to connect for VPN.
>>
>> In the satellite office, we simply have a Pix 501, with 6-8 client
>> desktops behind it. We will need all of them to be able to connect to
>> the Cisco VPN using the MS Windows VPN connection.
>>
>> Is there something i need to do to make this happen? Right now it
>> appears that one 1 of them at a time can connect.
>>
>> Thanks in advance.... I am not a cisco certified guy yet, but i plan on
>> working towards it someday soon.
>>
>> Rodney
>
thanks, will be going down there and trying it today!!

I will let you know

Posted by rodney on February 12, 2008, 1:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Sorry, i should have informed you that we are at version 6.3(5) for the
pix 501.

I already these entries in place.

Is there something else i should be looking for?

Yandy Ramirez wrote:
> Yes for windows PPTP clients you need to inspect PPTP at the PIX level.
> We ran into an issue like that.
>
> Versions <= 6.3
>
> Fixup protocol pptp 1723
>
> Also allow GRE on your access lists.
>
> Version >= 7.0
>
> pixfirewall(config)#policy-map global_policy
>
> pixfirewall(config-pmap)#class inspection_default
>
> pixfirewall(config-pmap-c)#inspect pptp
>
>
> Hope that helps.
>
> You may also need to allow GRE through.
>
>
> On 2/11/08 10:03 AM, in article 47b063be$0$8649$4c368faf@roadrunner.com,
>
>> We are setting up a temporary satellite office about 15 minutes away,
>> and we are running into a minor problem with the client connectivity
>> from that office.
>>
>> Ill explain the hardware real quick. In our main office, we have a PIX
>> 506e Firewall, with the 3005 Concentrator behind it for VPN. We are
>> using the MS client via PPTP to connect for VPN.
>>
>> In the satellite office, we simply have a Pix 501, with 6-8 client
>> desktops behind it. We will need all of them to be able to connect to
>> the Cisco VPN using the MS Windows VPN connection.
>>
>> Is there something i need to do to make this happen? Right now it
>> appears that one 1 of them at a time can connect.
>>
>> Thanks in advance.... I am not a cisco certified guy yet, but i plan on
>> working towards it someday soon.
>>
>> Rodney
>

Similar ThreadsPosted
Multiple immediate openings! Cisco engineers!! January 19, 2006, 1:12 pm
Cisco DHCP Multiple Subnets September 1, 2008, 4:29 pm
Cisco Avaya dot1q trunk issue March 22, 2006, 6:00 am
Wierd issue with Cisco 871w router January 19, 2007, 9:33 pm
Connecting to a Cisco router's Console port via Zterm - Issues August 1, 2007, 1:31 am
cisco 1604 win2003 server - routing issue October 28, 2005, 5:39 am
problem in connecting lansey ADSL modem with cisco catalyst 2950 switch. July 13, 2006, 8:21 am
3005 Concentrator L2L quesitons? May 9, 2006, 1:00 am
Bridge two DSL Connections? March 3, 2005, 5:19 pm
Odd question about serial connections December 26, 2005, 7:58 pm

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map