Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Error 721 - gre protocol?

Status
Not open for further replies.

hbalf1

MIS
Oct 23, 2003
71
GB
Hi
I have a PIX 506e and I am trying to enable a VPN via IA2004. It works if my access lists are:

access-list vpn01 permit tcp any host x.x.x.x eq 1723
access-list vpn01 permit tcp any host x.x.x.x eq 47
access-list vpn01 permit tcp any host x.x.x.x

Now if I remove the last line it fails. Obviously I do not want to leave the last line in because it allows any port to flow in (or so I understand.)

I also read somewhere that gre is not tcp, but should be ip. However if I try
access-list vpn01 permit ip any host x.x.x.x eq 47
then the editor does not recognisde the command.

Any ideas please?

Thanks Lewel
 
I am not familiar with PIX but with routers when you try to remove just one line of an access-list it actually removes the entire list. Are you sure that you are just removeing the one line and not the entire statement?
 
Hi
access-list vpn01 permit tcp any host x.x.x.x eq 1723
access-list vpn01 permit gre any host x.x.x.x
Was required
Lewej
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top