I'm setting up a netscreen 25 firewall to use NAT. All is working fine except that people can't VPN in (using PPTP preferably). (I want people to be able to VPN in to a VPN server on the inside and not use the built-in VPN abilities of the netscreen).
I'm finding messages everywhere saying that to allow me to do this, I have to allow in PPTP protocol, which I've done, but I also have to "allow protocol 47" - what exactly is meant by this? In the services rule, I can create a service with a specific IP type - is this what they mean? I've tried doing this - creating a service that allows all ports to all ports with IP proto 47 allowed, but this isn't working. Can anyone shine any light on what exactly "open protocol 47" means in terms of a netscreen firewall?
thanks alex