PPTP on PIX501.

Unanswered Question
Mar 15th, 2007

Hi all,

could someone help me where problem could be?

I did configuration like this:

sysopt connection permit-pptp

ip local pool mypool

10.10.10.1-10.10.10.10

vpdn username test password test2

vpdn group 1 accept dialin pptp

vpdn group 1 client configuration address local mypool

vpdn group 1 ppp authentication mschap

vpdn group 1 client authentication local

vpdn group 1 ppp encryption mppe 128 required

vpdn enable outside

After that I did connection to our PIX 501 and I successfully connected and obtained IP address. I didnt configure ACL. We have one server translated with static. But problem is that I cannot connect to this server throught VPN.

After that I have configured explicit ACL but output is the same.

Any suggestion?

BR

jl

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Kamal Malhotra Thu, 03/15/2007 - 08:22

Hi JL,

Did you configure nat0? Something like :

access-list nonat permit ip 10.10.10.0 255.255.255.240

nat (inside) 0 access-list nonat

We need to make sure that the retunr traffic is not getting nated.

HTH,

Please rate if it helps,

Regards,

Kamal

johnleeee Thu, 03/15/2007 - 14:33

Hi Karnal,

sorry I didnt write. Iv configured nat0.

Regards,

jl

Tshi M Fri, 03/16/2007 - 12:35

Do you mind posting your ACL or your entire config? Take out your password and public IP addresses.

Regards,

johnleeee Sun, 03/18/2007 - 07:44

Hi,

here is attached config which I a little bit

changed related to IP add and pass.

Any suggestions?

BR

jl

Attachment: 
Tshi M Sun, 03/18/2007 - 09:23

few things that I noticed in your config are:

I don't see any crypto and isakmp commands

1. you don't need "access-list Inter_net deny ip any any " since this is implied by the ACL rules.

2. This ACL "access-list Inter_LAN deny ip any any log 4" on your inside interface preventing all other traffic to be blocked.

3. I will change the ACL no_nat to:

access-list no_nat extended permit ip host 192.168.2.150 255.255.255.255 192.168.10.0 255.255.255.0

4. change the pool to 192.168.10.1-192.168.10.10 mask 255.255.255.0

johnleeee Thu, 03/22/2007 - 00:35

Hi,

last line in ACL Inter_net is only for logging.

It is not related to my problem.

I read examples of configuration PPTP on Cisco web site but crypto commands were not there.

Only if someone want to use ISAKMP with PPTP.

Other thing is that pool I use I think can be

arbitrary. But I can change it ...no problem and test it. So I will change no_nat too.

Any other suggestions?

BR

jl

alexandre.paradis Thu, 03/22/2007 - 05:30

What is the default gateway on your server?

Perhaps the traffic is getting to your server, but your server is not sending it back.

You might want to do some network sniffing to see where the traffic actually stops.

One other thing you can try; do a "show access-list" on your pix, and look at the hitcount of your nat0 access-list. If it doesn't increment, it is most likely that the traffic never gets out of your network.

Actions

This Discussion