Cisco ASA 5505 VPN issue

I just installed an ASA550 on my home network and now I have a problem with connecting 2 PPtP vpn connections using either of the XP or Vista VPN connections. These connnections worked fine until I installed the ASA. Now they both contact the remote VPN locations, but fails when trying to authenticate. The Vista client gives 'error 806: The VPN connection between your computer and the VPN server could not be completed.' From the XP clien, the error states 721:The remote computer did not respond.

Here is my current ASA config:

ASA Version 7.2(2)33 ! hostname ciscoasa domain-name default.domain.invalid enable password XXXXXXXXX encrypted names ! interface Vlan1 nameif inside security-level 100 ip address 192.168.0.254 255.255.255.0 ! interface Vlan2 nameif outside security-level 0 ip address dhcp setroute ! interface Ethernet0/0 switchport access vlan 2 ! interface Ethernet0/1 ! interface Ethernet0/2 ! interface Ethernet0/3 ! interface Ethernet0/4 ! interface Ethernet0/5 ! interface Ethernet0/6 ! interface Ethernet0/7 ! passwd XXXXXXXXX encrypted boot system disk0:/asa722-33-k8.bin ftp mode passive clock timezone CST -6 clock summer-time CDT recurring 1 Sun Apr 2:00 last Sun Oct 2:00 dns server-group DefaultDNS domain-name default.domain.invalid dns server-group Primary name-server 64.90.65.2 name-server 64.90.65.5 pager lines 24 logging asdm informational mtu inside 1500 mtu outside 1500 icmp unreachable rate-limit 1 burst-size 1 asdm image disk0:/asdm no asdm history enable arp timeout 14400 global (outside) 1 interface nat (inside) 1 0.0.0.0 0.0.0.0 timeout xlate 3:00:00 timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02 timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat

0:05:00 timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip- disconnect 0:02:00 timeout uauth 0:05:00 absolute http server enable http 192.168.0.0 255.255.255.0 inside no snmp-server location no snmp-server contact snmp-server enable traps snmp authentication linkup linkdown coldstart telnet 192.168.0.0 255.255.255.0 inside telnet timeout 5 ssh 192.168.0.0 255.255.255.0 inside ssh timeout 5 console timeout 0 dhcpd auto_config outside ! dhcpd address 192.168.0.50-192.168.0.81 inside dhcpd dns 204.72.181.35 204.72.181.35 interface inside dhcpd enable inside !

! class-map inspection_default match default-inspection-traffic ! ! policy-map type inspect dns preset_dns_map parameters message-length maximum 512 policy-map global_policy class inspection_default inspect dns preset_dns_map inspect ftp inspect h323 h225 inspect h323 ras inspect rsh inspect rtsp inspect esmtp inspect sqlnet inspect skinny inspect sunrpc inspect xdmcp inspect sip inspect netbios inspect tftp ! service-policy global_policy global ssl encryption des-sha1 rc4-md5 prompt hostname context Cryptochecksum:ba83de2e963d331ef2ce46d982e5e2d4 : end

Anyone have any thoughts on what I am missing or what I need to add? Any help or adivce is greatly appreciated.

Thanks

Reply to
dmj792
Loading thread data ...

I should add that the VPN connections are initiated from the inside of my ASA to remote VPN servers that I need to access for work.

Reply to
dmj792

conf t policy-map global_policy class inspection_default inspect pptp wr mem

Reply to
Brian V

I found my resolution. I had to add a policy map to inspect pptp.

Here is the link in case anyone else runs into the same issu.

formatting link

Reply to
dmj792

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.