Cisco Certification Issue with Cisco Pix 501, and MS VPN connecting to Cisco 3005 VPN? Multiple connections

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Issue with Cisco Pix 501, and MS VPN connecting to Cisco 3005 VPN? Multiple connections rhalljr 02-11-08
Posted by rhalljr on February 11, 2008, 10:03 am
Please log in for more thread options
We are setting up a temporary satellite office about 15 minutes away,
and we are running into a minor problem with the client connectivity
from that office.

Ill explain the hardware real quick. In our main office, we have a PIX
506e Firewall, with the 3005 Concentrator behind it for VPN. We are
using the MS client via PPTP to connect for VPN.

In the satellite office, we simply have a Pix 501, with 6-8 client
desktops behind it. We will need all of them to be able to connect to
the Cisco VPN using the MS Windows VPN connection.

Is there something i need to do to make this happen? Right now it
appears that one 1 of them at a time can connect.

Thanks in advance.... I am not a cisco certified guy yet, but i plan on
working towards it someday soon.

Rodney

Posted by Yandy Ramirez on February 11, 2008, 10:26 am
Please log in for more thread options
Yes for windows PPTP clients you need to inspect PPTP at the PIX level.
We ran into an issue like that.

Versions <= 6.3

Fixup protocol pptp 1723

Also allow GRE on your access lists.

Version >= 7.0

pixfirewall(config)#policy-map global_policy

pixfirewall(config-pmap)#class inspection_default

pixfirewall(config-pmap-c)#inspect pptp


Hope that helps.

You may also need to allow GRE through.


On 2/11/08 10:03 AM, in article 47b063be$0$8649$4c368faf@roadrunner.com,

> We are setting up a temporary satellite office about 15 minutes away,
> and we are running into a minor problem with the client connectivity
> from that office.
>
> Ill explain the hardware real quick. In our main office, we have a PIX
> 506e Firewall, with the 3005 Concentrator behind it for VPN. We are
> using the MS client via PPTP to connect for VPN.
>
> In the satellite office, we simply have a Pix 501, with 6-8 client
> desktops behind it. We will need all of them to be able to connect to
> the Cisco VPN using the MS Windows VPN connection.
>
> Is there something i need to do to make this happen? Right now it
> appears that one 1 of them at a time can connect.
>
> Thanks in advance.... I am not a cisco certified guy yet, but i plan on
> working towards it someday soon.
>
> Rodney


Posted by rhalljr on February 11, 2008, 10:48 am
Please log in for more thread options
Yandy Ramirez wrote:
> Yes for windows PPTP clients you need to inspect PPTP at the PIX level.
> We ran into an issue like that.
>
> Versions <= 6.3
>
> Fixup protocol pptp 1723
>
> Also allow GRE on your access lists.
>
> Version >= 7.0
>
> pixfirewall(config)#policy-map global_policy
>
> pixfirewall(config-pmap)#class inspection_default
>
> pixfirewall(config-pmap-c)#inspect pptp
>
>
> Hope that helps.
>
> You may also need to allow GRE through.
>
>
> On 2/11/08 10:03 AM, in article 47b063be$0$8649$4c368faf@roadrunner.com,
>
>> We are setting up a temporary satellite office about 15 minutes away,
>> and we are running into a minor problem with the client connectivity
>> from that office.
>>
>> Ill explain the hardware real quick. In our main office, we have a PIX
>> 506e Firewall, with the 3005 Concentrator behind it for VPN. We are
>> using the MS client via PPTP to connect for VPN.
>>
>> In the satellite office, we simply have a Pix 501, with 6-8 client
>> desktops behind it. We will need all of them to be able to connect to
>> the Cisco VPN using the MS Windows VPN connection.
>>
>> Is there something i need to do to make this happen? Right now it
>> appears that one 1 of them at a time can connect.
>>
>> Thanks in advance.... I am not a cisco certified guy yet, but i plan on
>> working towards it someday soon.
>>
>> Rodney
>
thanks, will be going down there and trying it today!!

I will let you know

Posted by rodney on February 12, 2008, 1:54 pm
Please log in for more thread options
Sorry, i should have informed you that we are at version 6.3(5) for the
pix 501.

I already these entries in place.

Is there something else i should be looking for?

Yandy Ramirez wrote:
> Yes for windows PPTP clients you need to inspect PPTP at the PIX level.
> We ran into an issue like that.
>
> Versions <= 6.3
>
> Fixup protocol pptp 1723
>
> Also allow GRE on your access lists.
>
> Version >= 7.0
>
> pixfirewall(config)#policy-map global_policy
>
> pixfirewall(config-pmap)#class inspection_default
>
> pixfirewall(config-pmap-c)#inspect pptp
>
>
> Hope that helps.
>
> You may also need to allow GRE through.
>
>
> On 2/11/08 10:03 AM, in article 47b063be$0$8649$4c368faf@roadrunner.com,
>
>> We are setting up a temporary satellite office about 15 minutes away,
>> and we are running into a minor problem with the client connectivity
>> from that office.
>>
>> Ill explain the hardware real quick. In our main office, we have a PIX
>> 506e Firewall, with the 3005 Concentrator behind it for VPN. We are
>> using the MS client via PPTP to connect for VPN.
>>
>> In the satellite office, we simply have a Pix 501, with 6-8 client
>> desktops behind it. We will need all of them to be able to connect to
>> the Cisco VPN using the MS Windows VPN connection.
>>
>> Is there something i need to do to make this happen? Right now it
>> appears that one 1 of them at a time can connect.
>>
>> Thanks in advance.... I am not a cisco certified guy yet, but i plan on
>> working towards it someday soon.
>>
>> Rodney
>

Similar ThreadsPosted
Issue with Cisco Pix 501, and MS VPN connecting to Cisco 3005 VPN? Multiple connections February 11, 2008, 10:03 am
Multiple immediate openings! Cisco engineers!! January 19, 2006, 1:12 pm
Cisco DHCP Multiple Subnets September 1, 2008, 4:29 pm
Cisco Avaya dot1q trunk issue March 22, 2006, 6:00 am
Wierd issue with Cisco 871w router January 19, 2007, 9:33 pm
Connecting to a Cisco router's Console port via Zterm - Issues August 1, 2007, 1:31 am
problem in connecting lansey ADSL modem with cisco catalyst 2950 switch. July 13, 2006, 8:21 am
3005 Concentrator L2L quesitons? May 9, 2006, 1:00 am
Bridge two DSL Connections? March 3, 2005, 8:19 pm
Odd question about serial connections December 26, 2005, 7:58 pm
Multiple public IP behind PIX 501 December 1, 2005, 7:43 am
Multiple public IP behind PIX 501 December 1, 2005, 7:44 am
switch port on multiple vlans March 21, 2005, 6:21 pm
Multiple OSPF Stub Areas March 17, 2006, 5:56 pm
multiple ethernet router choice September 11, 2006, 10:36 am