Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

PPTP outbound and IOS Zone Based Policy Firewalling

I have a client trying to use PPTP outbound from a host on their DMZ. Their zone based policy firewall config appears essentially correct and all other traffic is egressing the 3845 router (DMZ to Internet) without issue. I had them add "match protocol pptp" to their inspect for that zone-pair. But he's still got no joy. Are there known problems with PPTP and ZBPF? Long ago there were problems with PPTP and PAT but I thought those had been resolved way back. (Please don't ask "why PPTP??" - it wasn't MY idea!) :-)

class-map type inspect match-any dmz-inet-ports

description ***DMZ to inet Access Ports***

match protocol pptp

match protocol icmp

match protocol tcp

match protocol udp

The image: c3845-advipservicesk9-mz.124-11.XW8.bin

1 REPLY

Re: PPTP outbound and IOS Zone Based Policy Firewalling

if there are any ACL's - please supply...and any debug's would be very helpfull.

HTH>

178
Views
0
Helpful
1
Replies
CreatePlease to create content