Re: VPN Across Firewall

From: Rama Krishna Amaravadi [MSFT] (ramamar_at_online.microsoft.com)
Date: 06/17/04


Date: Thu, 17 Jun 2004 16:29:56 +0530

Ryan,
Make sure that the following ports are opened on the PIX Firewall:
TCP port 1723
IP protocol 47 to allow GRE packets

Thanks,
Rama Amaravadi

-- 
This posting is provided "AS IS" with no warranties and confers no rights.
"Ryan Stewart" <nastypup@pacbell.net> wrote in message
news:Dcozc.2278$Xs2.1280@newssvr27.news.prodigy.com...
> I am trying to initiate a connection across our pix firewall...
>
> The source is a win2000 server the destination is a win2003 server (in
> our dmz).
> I am attempting to make an PPTP connection.
>
> On the pix I have opened up traffic for all ports between the two
> servers. We are running version 5.3 of the pix software
>
> I put a packet sniffer on the source computer and it seems to be sending
> out the packets but the destination isnt receiving them back. The
> connection ends up failing saying there was no answer.
>
> I know the destination pc is configured correctly because i can initiate
>   a connection from another pc on the same side of the firewall...
>
> Is there anything I am might be missing here? IS the pix not compatible
> with this?
>


Relevant Pages

  • Re: Trouble accessing Outlook Web Access from behind firewall
    ... When starting the firewall I also set ... > rejected and dropped packets are logged, however I see nothing in my log ... > # Higher ports needed to accept incoming/outgoing calls ...
    (comp.security.firewalls)
  • Clever firewall rules
    ... This one drops all incoming packets that are not SYN packets, ... Either way, both rules are in my firewall, and it produces the results I'm ... similar rule that would log people who ping me, ... I have some basic rules that just open the ports that I ...
    (Focus-Linux)
  • Re: HELP ME
    ... > transparently either by using a stealth firewall or a totally transparent ... > firewall any attackers that try to connect to firewalled ports will get ... > [The firewall should be configured to drop offending packets silently, ... >> DO IF SOME TCP CONNECTION RECIVE TO MY BOX, THE KERNEL IGNORE IT AND ...
    (FreeBSD-Security)
  • RE: Does the Cisco PIX have an equivalent of the IPFW "fwd" action?
    ... PIX is not IOS, and AFAIK it was not designed for complex network solutions. ... I'm setting up a FreeBSD transparent Web proxy for a client which has an old ... Cisco PIX firewall router. ... packets will not be that of the proxy machine itself) and do transparent caching. ...
    (freebsd-net)
  • Re: Help With firewall ports
    ... make design of your firewall. ... recommend "default deny" approach. ... into your box except to ports you explicitly allow. ... close all packets with FIN, URG and PSH flags on ...
    (Security-Basics)