Re: Incoming VPN issues...works for some, but not all.

From: Robert L [MS-MVP] (noreply_at_hotmail.com)
Date: 05/19/04


Date: Wed, 19 May 2004 13:04:29 -0500

first of all, why do you use PIX as VPN server? quoted from
http://www.ChicagoTech.net
Error 721: Remote PPP peer or computer is not responding. If you have tried
many thing other people suggest like rebooting, reloading hardware and
re-installing the VPN or dial in connection, you still get the same problem.
I will suggest to check the router settings and make sure TCP Port 1723, IP
Protocol 47 (GRE) are opened. Also make sure that the router has the PPTP
enabled and not firewall block the traffic. On the RAS server, check the
DHCP settings.

-- 
For more and other information, go to  http://www.ChicagoTech.net
Don't send e-mail or reply to me except you need consulting services. 
Posting on MS newsgroup will benefit all readers and you may get more help.
Robert Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN, Anti-Virus, Tips & Troubleshooting on 
http://www.ChicagoTech.net
This posting is provided "AS IS" with no warranties.
"Mark R." <markr@training{nospam}channel.com> wrote in message 
news:eed201c43d44$147b6c80$a301280a@phx.gbl...
>I have a native mode W2K AD environment. On the perimeter
> is a PIX 515 (sorry, not ISA Server, yet) as is my
> perimeter defense. the PIX also does P-NAT for our office.
> On the inside LAN I have a W2K member server that only
> exists to provide incoming VPN authentication and DHCP to
> requestors. On the PIX is a static route and access list
> that moves all PPTP/GRE traffic into the network to the
> VPN server for authentication. However, here is the issue.
> Only some users are allowed authentication, and then they
> only remain connected for about a minute and a half. The
> ones that never connect get all the way to "verifying
> username and password", it sits there for about 30
> seconds, then the "error 721" box pops up telling you that
> the "remote computer did not respond...yadda, yadda". The
> event logged on the VPN server for the clients that
> successfully connect and are dropped shortly thereafter is
> a happy message about being logged off because of user
> request (sorry, don't have the exact event id). We've
> tried both W2K and XP clients, with encryption on and off
> with the same results. Also, the users that can connect
> can do it from pretty much any machine, while the ones
> that cannot connect are in the same boat (cannot connect
> from anywhere). We're not doing any fancy-schmancy
> VLANning or weird layer 3 switching (I hope...will have to
> check further up the food chain on that one).
> Anyhow...sorry to ramble. Lemme know if there are ideas
> out there.
>
> Mark 


Relevant Pages

  • Win2K3 L2TP VPN server behind Cisco PIX firewall - Help!
    ... I am trying to setup a Windows 2003 L2TP VPN gateway behind a Cisco PIX ... separate path past our PIX firewall by dual-porting the VPN server across the ... access-list outside_access_in remark permit isakmp from any to any ...
    (microsoft.public.windows.server.networking)
  • PIX 501 - A few problems configuring
    ... Auditors like buzzwords and disks full of log files, and they seemed to believe the PIX 501 satisfied both. ... if I want the PIX to act as a VPN server I don't think that's gonna work. ... I'm thinking Cisco's "Linksys to Cisco Trade-Up Program" should be renamed to Trade-Down. ...
    (comp.dcom.sys.cisco)
  • Re: Incoming VPN issues...works for some, but not all.
    ... why do you use PIX as VPN server? ... >> exists to provide incoming VPN authentication and DHCP ...
    (microsoft.public.win2000.ras_routing)
  • VPN With PIX
    ... I sneed to setup a VPN Server using PIx 500 series. ... can i use my server's local authentication to use in my VPN ...
    (microsoft.public.win2000.ras_routing)
  • Re: VPN connection
    ... > I have a static NAT rules set up that points straight to the 2003 box. ... > IAS with the PIX device set up exactly like it was on the 2000 box. ... There are many way to rig up VPN,...Only one can be acting as the VPN Server ...
    (microsoft.public.windows.server.sbs)