Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 501-- VPN pass-through?? Need help...

Status
Not open for further replies.

jlionhrt

Technical User
Aug 28, 2003
2
US
Hi, like so many posts I have read, I too am not familiar with firewalls of this caliber. I have on my home LAN, an NFR version of a Pix 501 that is connected behind my cable modem. I installed it about a year ago and let it run with defaults from the beginning. I also have a dial-up ISP configured as a back-up. I am now in a situation where I need to VPN to another location that uses a Netopia router and is configured to forward port 1723/VPN traffic onward.
Here is the problem....
I have configured the VPN connection to that Netopia on my XP machine using the Windows client, and it works fine when I connect with my dial-up. But I need speed so want to go through my broadband connection, however, the PIX will not let me connect.... it hangs up and errors on "Validating User and Password". I have created a new rule to allow PPTP traffic (which is being used for the VPN), and I still get the same error..... I suppose I shouldn't posses such a high-end firewall for my SOHO, but can anybody offer some "simple" soultion that doesn't require me having a PhD??
 
You need to open tcp port 1723 and ip protocol 47 on the PIX. You will also need a static translation it will not work through PAT or if you are running 6.3 you need the command "fixup protocol pptp 1723" instead of the static translation. Use the link below as a guideline:


Hope this helps!
 
jlionhrt,

static nat will have to be used with version 6.2

pat can be used with version 6.3 and the fixup for pptp 1723

good luck
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top