PPTP on PIX501.

Unanswered Question
Mar 15th, 2007
User Badges:

Hi all,

could someone help me where problem could be?

I did configuration like this:

sysopt connection permit-pptp

ip local pool mypool

vpdn username test password test2

vpdn group 1 accept dialin pptp

vpdn group 1 client configuration address local mypool

vpdn group 1 ppp authentication mschap

vpdn group 1 client authentication local

vpdn group 1 ppp encryption mppe 128 required

vpdn enable outside

After that I did connection to our PIX 501 and I successfully connected and obtained IP address. I didnt configure ACL. We have one server translated with static. But problem is that I cannot connect to this server throught VPN.

After that I have configured explicit ACL but output is the same.

Any suggestion?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Kamal Malhotra Thu, 03/15/2007 - 08:22
User Badges:
  • Cisco Employee,

Hi JL,

Did you configure nat0? Something like :

access-list nonat permit ip

nat (inside) 0 access-list nonat

We need to make sure that the retunr traffic is not getting nated.


Please rate if it helps,



johnleeee Thu, 03/15/2007 - 14:33
User Badges:

Hi Karnal,

sorry I didnt write. Iv configured nat0.



Tshi M Fri, 03/16/2007 - 12:35
User Badges:
  • Silver, 250 points or more

Do you mind posting your ACL or your entire config? Take out your password and public IP addresses.


johnleeee Sun, 03/18/2007 - 07:44
User Badges:


here is attached config which I a little bit

changed related to IP add and pass.

Any suggestions?



Tshi M Sun, 03/18/2007 - 09:23
User Badges:
  • Silver, 250 points or more

few things that I noticed in your config are:

I don't see any crypto and isakmp commands

1. you don't need "access-list Inter_net deny ip any any " since this is implied by the ACL rules.

2. This ACL "access-list Inter_LAN deny ip any any log 4" on your inside interface preventing all other traffic to be blocked.

3. I will change the ACL no_nat to:

access-list no_nat extended permit ip host

4. change the pool to mask

johnleeee Thu, 03/22/2007 - 00:35
User Badges:


last line in ACL Inter_net is only for logging.

It is not related to my problem.

I read examples of configuration PPTP on Cisco web site but crypto commands were not there.

Only if someone want to use ISAKMP with PPTP.

Other thing is that pool I use I think can be

arbitrary. But I can change it ...no problem and test it. So I will change no_nat too.

Any other suggestions?



alexandre.paradis Thu, 03/22/2007 - 05:30
User Badges:

What is the default gateway on your server?

Perhaps the traffic is getting to your server, but your server is not sending it back.

You might want to do some network sniffing to see where the traffic actually stops.

One other thing you can try; do a "show access-list" on your pix, and look at the hitcount of your nat0 access-list. If it doesn't increment, it is most likely that the traffic never gets out of your network.


This Discussion