Re: ISA 06 PPTP VPN via NAT
- From: "Thomas Tomiczek" <t.tomiczek@xxxxxxxxxxxxxx>
- Date: Wed, 31 Jan 2007 13:14:57 +0100
PPTP does not only use port 1723, but also TCP Sub-Protocol 47 - GRE.
If this is not properly handled and filtered, you will get severe issues. Like "server does not respond". In fact, GRE packets are what is used to transfer the data, while the TCP connection is only used for command channels.
A LOT of cheap/stupid equipment and admins are unaware of this fact - and then, for example, filter out GRE.
"Daniel Hooper" <daniel.hooper@xxxxxxxxxxxxxx> wrote in message news:CCA45108-2B0C-4873-9C7C-8080A9FDBE04@xxxxxxxxxxxxxxxx
Hi,
I've recently stumbled on a pearler that I can not seem to get my head around, hopefully somebody here can point me in the right direction.
I have an ISA 2006 installation running on a Windows 2003 R2 machine, the system has only 2 network interfaces, a public and an internal. If any of my users try and connect to a remote VPN server they recieve an error and the connection does not iniaite, I can see packets on port tcp/1723 leaving the box, none of the users are running the ISA firewall client.
My ISP connection is just plain old ethernet with no pppoe just a static IP address, if I plug my laptop into it I can VPN no problems at all, my cisco PIX can also NAT PPTP connections out of it, I've even gone so far as rolling back to Windows 2003 & ISA 2004 with no success, formatted and started again a couple of times.
I also sense that it's something that the provider is doing or filtering, another customer down the street on the same provider with the exact same ISA 06 configuration has the exact same issue.
Where can I look to put this back onto the provider? I've complained / whinged / asked / threatend them many times with no result, they say it's an issue with ISA and they are semi correct as I can use any other NAT enabled box and the PPTP vpn's work.
Cheerio
Daniel Hooper
.
- References:
- ISA 06 PPTP VPN via NAT
- From: Daniel Hooper
- ISA 06 PPTP VPN via NAT
- Prev by Date: ISA 06 PPTP VPN via NAT
- Previous by thread: ISA 06 PPTP VPN via NAT
- Index(es):
Relevant Pages
|