Re: VPN

From: sunday (anonymous_at_discussions.microsoft.com)
Date: 04/12/04


Date: Mon, 12 Apr 2004 13:28:04 -0700

Thanks Steven for your quick response.

I have now configured protocol 47 gre in my pix to permit
connections.
I am using a dial up from my home and i dont have any
external router/ firewall setup at home. Should i need to
check for any internal firewall/ router in the XP box at
home. ( If so how do i find it )
I will also try to connect through PPTp instead of auto
when i reach home today.
I use kiwisyslog , hope that may help me to look into the
dropped/ blocked ones once i try this tonight.
I will update you the outcome. In the meantime, if you
have answers on the above. Let me know. Appreciate again
for your response.

Thanks
Sunday

>-----Original Message-----
>I am not familiar with pix, but you may need to configure
your router device at home
>to allow pptp passthrough if it has that option and at
the office you need to let the
>firewall allow port 1723 tcp and protocol 47 GRE or
sometimes referred to as pptp
>passthrough. I see you have port 1723 configured, so
maybe you just have to configure
>protocol 47 GRE. The pix will also need to port forward
to the proper computer on
>your office lan by it's IP address. Also configure your
XP home VPN connectoid to use
>"pptp" as type of vpn instead of auto as it will try
using l2tp first by default. It
>may also be helpful to look in the logs of your pix
firewall to see what packets are
>being dropped/blocked. The link below may be helpful. ---
 Steve
>
>http://www.microsoft.com/resources/documentation/WindowsSe
rv/2003/enterprise/proddocs/en-us/Default.asp?
url=/resources/documentation/WindowsServ/2003/enterprise/pr
oddocs/en-us/sag_vpn_und13.asp
>
>
>"Sunday" <anonymous@discussions.microsoft.com> wrote in
message
>news:1b71c01c420b6$85185e80$a401280a@phx.gbl...
>> I have a windows XP Home edition at home and is trying
to
>> connect to a computer running windows 2000 professional
in
>> the office.
>>
>> I have enabled the VPN to accept connections in the
>> Windows 2000 professional. When i try to connect from my
>> XP i get errors. I have a PIX 501 firewall in between. I
>> have updated my firewall with the below lines. Still i
get
>> the errors.
>> access-list 101 permit tcp any host 192.168.0.5 eq 1723
>> access-list 101 permit tcp any host 216.x.x.x eq 1723
>> access-list 101 permit udp any host 216.x.x.x eq 1723
>> access-list 101 permit udp any host 192.168.0.5 eq 1723.
>> Is their any thing i need to do at my XP or Windows 2000
>> or the PIX for me to enable a VPN connection from my
home
>> to the office.
>>
>> Thanks
>> Sunday
>>
>
>
>.
>



Relevant Pages

  • Re: [fw-wiz] Problem with Mac and PIX Firewall
    ... That's a heck of a reason to switch OS's! ... > I am trying to hook up a mac running OSX 10.3.9 to the DMZ on our PIX ... > of the firewall. ... It does not happen with Windows. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Scheduling PIX commands
    ... I suggested being within ear shot of the rack containing the Firewall at 2 ... dependent of monitoring the state of connections (back to the client and / ... clearing the xlate table, i dont see how that could go very wrong. ... We've just made some changes to our PIX config, ...
    (Firewall-Wizards)
  • RE: where should I start? help!
    ... I do not believe it is the PIX, ... Regards, ... are forced connections rather than using auto. ... Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! ...
    (Security-Basics)
  • Inbound connections on a 515e without NAT
    ... I have a PIX 5i5E configured that permits outbound connections ... However I can't get it to permit inbound ... global 1 interface ... Even though, if this worked, it would allow inbound connections to every system behind A.B.50.14 on the PIX. ...
    (comp.dcom.sys.cisco)
  • 404 trying to access pdm
    ... Trying to get pdm working on our PIX 6.2 Firewall, ... luck. ... I have it enabled and set up to accept connections from my ...
    (comp.dcom.sys.cisco)