cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
658
Views
0
Helpful
2
Replies

PPTP VPN is not establishing...

devang_etcom
Level 7
Level 7

Tnl 27 PPTP: Tunnel created; peer initiated

Tnl 27 PPTP: SCCRQ-ok -> state change wt-sccrq to estabd

Tnl/Cl 27/27 PPTP: l2x store session: tunnel id 27, session id 27, hash_ix=27

Tnl/Cl 27/27 PPTP: vacc-ok -> state change wt-vacc to estabdPPTP mgmt daemon wak

eup, major = 1

Tnl 27 PPTP: timeout -> state change estabd to estabdPPTP mgmt daemon wakeup, ma

jor = 1

Tnl 27 PPTP: timeout -> state change estabd to estabd

Tnl 27 PPTP: timeout -> echo state change Idle to wt-echorp

Tnl 27 PPTP: EchoRP -> state change estabd to estabd

Tnl 27 PPTP: EchoRP -> echo state change wt-echorp to IdlePPTP mgmt daemon wakeu

p, major = 1

Tnl 27 PPTP: timeout -> state change estabd to estabd

Tnl 27 PPTP: timeout -> echo state change Idle to wt-echorp

Tnl 27 PPTP: EchoRP -> state change estabd to estabd

Tnl 27 PPTP: EchoRP -> echo state change wt-echorp to Idle

Tnl/Cl 27/27 PPTP: ClearReq -> state change estabd to terminal

Tnl/Cl 27/27 PPTP: Destroying session

Tnl 27 PPTP: no-sess -> state change estabd to wt-stprp

Tnl 27 PPTP: StopCCRQ -> state change wt-stprp to wt-stprp

Tnl 27 PPTP: Destroy tunnel

can any one help me to rectify this issue?

i am using PIX 515 version 6.3 for PPTP VPN and i have microsoft client... i tried it but its giving above error so please help me for the same...

regards

Devang

2 Replies 2

5220
Level 4
Level 4

Hi Devang,

The problem is that when you initiate a PPTP from inside, it goes as a TCP packet, but then the server will initiate a GRE tunnel from outside. This traffic will be dropped by the firewall.

http://www.microsoft.com/technet/community/columns/cableguy/cg0103.mspx

You have two alternatives:

1. add PPTP to inspection: fixup protocol pptp 1723 (the default port)

2. add an ACL statement on the outside interface permitting GRE from the server to the LAN (Public, that is, NATed IPs).

Please rate if this helped.

Regards,

Daniel