PPTP & PIX Question

Hi I have a range of static IP's as part of a /29 assigned from our ISP I am using one of these IP's for VPN usage The RRAS server is located in the DMZ on This is what I am seeing in the PDM log

pix(config)# sh pdm log | i

6|Feb 23 2007 11:32:53|302013: Built inbound TCP connection 20758708 for outside : ( to dmz1: (203.59.123 .46/1723) 6|Feb 23 2007 11:32:53|106015: Deny TCP (no connection) from t o flags SYN ACK on interface inside

I assume what is happening is that port 1723 is coming in on and is being passed to the RRAS server on on port 1723 I have an access list that says anything ( from the outside coming in on any TCP port pass it to on port 1723

Can anyone tell me where I am going wrong and why it is trying to reference the inside i/f when I have not specified anything here?



Reply to
Loading thread data ...

Does the DMZ device have multiple interfaces? Or is your DMZ seperated from your main LAN by way of a VLAN?

The log messages are consistant with the reply from the DMZ device

-somehow- being routed to the inside interface. Is that "physically impossible" in your network, or is it just "logically impossible (assuming nothing has been misconfigured)"?

Reply to
Walter Roberson

Hi Walter Good question. The DMZ is a single interface on the PIX that connects to a 100Mb hub, this is where the proxy server lives as well as the mail marshall server and of course the RRAS server. The RRAS server has two interfaces one in the DMZ and one in it's own VLAN that connects back to the main Catalyst Switch, the catalyst switch is simply running RIP as is the PIX Here is the show route command and PEWVP01 is the RRAS server. is the DMZ interface on the PIX pix# sh route outside Gateway837 1 OTHER static inside VPNContivity 1 OTHER static dmz1 1 CONNECT static dmz1 PEWMM01 1 OTHER static dmz1 PEWVP01 1 OTHER static dmz2 1 CONNECT static dmz3 1 CONNECT static dmz4 1 CONNECT static inside BalcattaLAN 1 OTHER static inside DataCentreLAN 1 CONNECT static inside ScoresbyLAN 2 OTHER static inside ErmingtonLAN 2 OTHER static inside UnderwoodLAN 1 OTHER static inside UnleyLAN 1 OTHER static inside howanrouter 1 OTHER static outside 1 CONNECT static

pix# sh rip rip inside default version 2 rip dmz1 default version 2

Do you think it's the RIP thats doing it? And with that would I be better off confioguring RIP on the DMZ interface of the RRAS server?

Cheers Scott

Reply to

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.