Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

PIX 515 with PPTP VPN

Status
Not open for further replies.

rdoucet

IS-IT--Management
May 11, 2001
15
0
0
US
I have set up a PIX 515 to use PPTP as the VPN using the Windows VPN client. I can log in with NT, 2000 and ME, but when trying to log in with Windows 98 I get the error message error, "691 Access denied because username and/or password is invalid on the domain"

Anyone know of a way around that? It is ONLY with 98.

Thanks,
BK
 
BK,

I don't have an answer for your '98 dilemma, but rather a question. I have set up a PIX515 for PPTP using 2000 client. You said your users can "log in". Do you mean domain login (network neighborhood, drive mappings etc) or do you simply mean PPTP login to the 515. I ask because I can't get a domain logon.

Regards
smtm$$$$

 
Actually, I figured it out. My problem was that in Windows 98 the last domain you tried is written to the registry and added to the PPTP login name. So mine would be DOMAIN\rdoucet, even though I only put rdoucet. I would set the vpdn username in the pix to DOMAIN\rdoucet.

Your problem is that it doesn't know what to do once it gets there. In Windows 98 and NT it's no big deal. In 2000 it's a pain. I'll stick to 2000 since that's your problem.

The first thing you have to do is to set your 2000 machine to NOT log into a domain, but to log into a workgroup of the same name. Let's say your domain name is DOMAIN. Set it to log into a Workgroup called DOMAIN. Of course you have to reboot. Now, connect to your PIX515 with PPTP. Once there, change your settings from a workgroup to a domain, with the same name of DOMAIN again. It will authenticate you, and then you still have to reboot, again that's OK. It only has to do this once, and from then on it will work.

Now, for this to work at all the computer has to know where the PDC is. In my case I had several different networks and domains, so I had to set the WINs server for the particular user in their dial-up adapter. But, if you are dealing with a single domain it's easier to set the WINs server in the PIX PPTP setup. Of course you can set multiple domain listings in a single WINs, but I won't go off on that one.

I hope this helps, GOD BLESS AMERICA!!
 
I have setup a VPN to my PIX 520 using a PPTP tunnel and the Windows CMAK. I can get onto the domain and browse the network. However, does anyone know how I can kick off a login script? We are trying to convert over from a windows 2000 RAS server and I am stuck. Please help.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top