PPTP using Windows RRAS behind a 1801 ISR

Unanswered Question
Feb 15th, 2008
User Badges:


We have a Windows server with RRAS configured for dial in vpn and have just implemented a cisco 1801 Integrated Service Router with Advanced IP/Security bundle.

The router has port 1723 mapped to the local server private ip and were using NAT on the private network

Our users are able to connect to the public address but are unable to get past the verifying username and password stage to complete the vpn and get a 631 error.

I have read somewhere that the 1801 needs to have GRE configured for PPTP to terminate.

Does anybody know how to add this to the current configuration of our router?

*See attached config*

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
rkazmierczak Mon, 02/18/2008 - 12:05
User Badges:


if possible configure static NAT rather than static PAT (PAR) and allow gre and pptp in the access-list

ip nat inside source static

ip access-list ext OUTSIDE_IN

permit gre any h

permit tcp any h eq 1723

This should work :)


This Discussion