Re: VPN

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Steven L Umbach (n9rou_at_nospam-comcast.net)
Date: 04/12/04


Date: Mon, 12 Apr 2004 20:35:45 GMT

OK. The internal ICF firewall in XP should not need any additional configuration for
pptp I believe as it will allow outbound access. If you are using a different
software firewall you may need to configure it, but usually it would prompt you when
it detected a new application trying to access the internet. --- Steve

"sunday" <anonymous@discussions.microsoft.com> wrote in message
news:1bbee01c420cc$a88719e0$a101280a@phx.gbl...
> Thanks Steven for your quick response.
>
> I have now configured protocol 47 gre in my pix to permit
> connections.
> I am using a dial up from my home and i dont have any
> external router/ firewall setup at home. Should i need to
> check for any internal firewall/ router in the XP box at
> home. ( If so how do i find it )
> I will also try to connect through PPTp instead of auto
> when i reach home today.
> I use kiwisyslog , hope that may help me to look into the
> dropped/ blocked ones once i try this tonight.
> I will update you the outcome. In the meantime, if you
> have answers on the above. Let me know. Appreciate again
> for your response.
>
> Thanks
> Sunday
>
> >-----Original Message-----
> >I am not familiar with pix, but you may need to configure
> your router device at home
> >to allow pptp passthrough if it has that option and at
> the office you need to let the
> >firewall allow port 1723 tcp and protocol 47 GRE or
> sometimes referred to as pptp
> >passthrough. I see you have port 1723 configured, so
> maybe you just have to configure
> >protocol 47 GRE. The pix will also need to port forward
> to the proper computer on
> >your office lan by it's IP address. Also configure your
> XP home VPN connectoid to use
> >"pptp" as type of vpn instead of auto as it will try
> using l2tp first by default. It
> >may also be helpful to look in the logs of your pix
> firewall to see what packets are
> >being dropped/blocked. The link below may be helpful. ---
> Steve
> >
> >http://www.microsoft.com/resources/documentation/WindowsSe
> rv/2003/enterprise/proddocs/en-us/Default.asp?
> url=/resources/documentation/WindowsServ/2003/enterprise/pr
> oddocs/en-us/sag_vpn_und13.asp
> >
> >
> >"Sunday" <anonymous@discussions.microsoft.com> wrote in
> message
> >news:1b71c01c420b6$85185e80$a401280a@phx.gbl...
> >> I have a windows XP Home edition at home and is trying
> to
> >> connect to a computer running windows 2000 professional
> in
> >> the office.
> >>
> >> I have enabled the VPN to accept connections in the
> >> Windows 2000 professional. When i try to connect from my
> >> XP i get errors. I have a PIX 501 firewall in between. I
> >> have updated my firewall with the below lines. Still i
> get
> >> the errors.
> >> access-list 101 permit tcp any host 192.168.0.5 eq 1723
> >> access-list 101 permit tcp any host 216.x.x.x eq 1723
> >> access-list 101 permit udp any host 216.x.x.x eq 1723
> >> access-list 101 permit udp any host 192.168.0.5 eq 1723.
> >> Is their any thing i need to do at my XP or Windows 2000
> >> or the PIX for me to enable a VPN connection from my
> home
> >> to the office.
> >>
> >> Thanks
> >> Sunday
> >>
> >
> >
> >.
> >



Relevant Pages

  • Re: which firewall?
    ... Zone Alarm is better in that it also restricts outbound access and can have ... does not reduce Internet Explorer ... for other users of the computer, then ICF built in firewall is perfectly ...
    (microsoft.public.security)
  • Re: How to disable Internet Explorer
    ... another browser or even use Windows Explorer to browse the internet. ... A fairly inexpensive firewall can block all unwanted ... outbound access and manage it by ip address, address range, or subnet. ...
    (microsoft.public.security)
  • Re: Pf allow outgoing pptp clients
    ... > internal network behind a OpenBSD 3.3 PF firewall to connect to a PPTP ... The OpenBSD firewall also acts as an Internet gateway, ... paas out on $external_if proto gre keep state ...
    (comp.unix.bsd.openbsd.misc)
  • Re: Pf allow outgoing pptp clients
    ... >>internal network behind a OpenBSD 3.3 PF firewall to connect to a PPTP ... The OpenBSD firewall also acts as an Internet gateway, ...
    (comp.unix.bsd.openbsd.misc)
  • Pf allow outgoing pptp clients
    ... internal network behind a OpenBSD 3.3 PF firewall to connect to a PPTP ... The OpenBSD firewall also acts as an Internet gateway, ...
    (comp.unix.bsd.openbsd.misc)