01-19-2007 02:06 PM
Tnl 27 PPTP: Tunnel created; peer initiated
Tnl 27 PPTP: SCCRQ-ok -> state change wt-sccrq to estabd
Tnl/Cl 27/27 PPTP: l2x store session: tunnel id 27, session id 27, hash_ix=27
Tnl/Cl 27/27 PPTP: vacc-ok -> state change wt-vacc to estabdPPTP mgmt daemon wak
eup, major = 1
Tnl 27 PPTP: timeout -> state change estabd to estabdPPTP mgmt daemon wakeup, ma
jor = 1
Tnl 27 PPTP: timeout -> state change estabd to estabd
Tnl 27 PPTP: timeout -> echo state change Idle to wt-echorp
Tnl 27 PPTP: EchoRP -> state change estabd to estabd
Tnl 27 PPTP: EchoRP -> echo state change wt-echorp to IdlePPTP mgmt daemon wakeu
p, major = 1
Tnl 27 PPTP: timeout -> state change estabd to estabd
Tnl 27 PPTP: timeout -> echo state change Idle to wt-echorp
Tnl 27 PPTP: EchoRP -> state change estabd to estabd
Tnl 27 PPTP: EchoRP -> echo state change wt-echorp to Idle
Tnl/Cl 27/27 PPTP: ClearReq -> state change estabd to terminal
Tnl/Cl 27/27 PPTP: Destroying session
Tnl 27 PPTP: no-sess -> state change estabd to wt-stprp
Tnl 27 PPTP: StopCCRQ -> state change wt-stprp to wt-stprp
Tnl 27 PPTP: Destroy tunnel
can any one help me to rectify this issue?
i am using PIX 515 version 6.3 for PPTP VPN and i have microsoft client... i tried it but its giving above error so please help me for the same...
regards
Devang
01-20-2007 02:47 AM
Hi Devang,
The problem is that when you initiate a PPTP from inside, it goes as a TCP packet, but then the server will initiate a GRE tunnel from outside. This traffic will be dropped by the firewall.
http://www.microsoft.com/technet/community/columns/cableguy/cg0103.mspx
You have two alternatives:
1. add PPTP to inspection: fixup protocol pptp 1723 (the default port)
2. add an ACL statement on the outside interface permitting GRE from the server to the LAN (Public, that is, NATed IPs).
Please rate if this helped.
Regards,
Daniel
01-20-2007 04:10 AM
Even better example:
Please rate if this helped.
Regards,
Daniel
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide