cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
446
Views
0
Helpful
4
Replies

Coneecting from a system beind pix to a win2k server through vpn

kjanakiraman
Level 1
Level 1

Hi,

I have a cisco Pix 515 with vpn enabled. I need to connect to a remote server (windows 2000)and then go to a particular system with private ip address using vpn. The Client is having win2k vpn configuration. How should i proceed. He has given me his public vpn server ip address with the username and password and the private ip address of a system inside. When i try from outside the firewall it is working fine. What is the procedure that i need to follow when i am trying from inside the firewall. Should i need to have a cisco vpn client? Can some one adivce me how to proceed.

Thanks in Advance

J.Karthik

4 Replies 4

paqiu
Level 1
Level 1

Hi Karthik,

PPTP over PAT for the PIX is not supported in the current version.

This is reason when you try to connect behind the PIX, it will not work.

You only can do static translation , it should be fine.

PIX outside is 200.200.200.200

I assume that you have extral public ip address 200.200.200.201 and your PC inside ip address is 192.168.1.201

static (inside, outside) 200.200.200.201 192.168.1.201

Then open tcp 1723 and gre for PPTP pass through: x.x.x.x is remote w2k server:

conduit permit tcp 200.200.200.201 host x.x.x.x eq 1723

conduit permit gre any any

Best Regards,

Thanks a lot for your reply. It worked perfectly. I believe this is not a full fledged vpn. For Example If i want to have a site to site vpn with this client who is having windows 2000 how is this possible? Can you Please advice me what are the other options? Other Question is that if i have a client with checkpoint firewall and vpn in that case how should i proceed.

Thanks and Regards

J.Karthik

Hi Karthik,

You can creat IPSEC VPN tunnel from your PIX to Windows 2000 server:

http://www.cisco.com/warp/customer/707/2000.html

If you want to creat IPSEC to checkpoint firewall, here is the sample config:

http://www.cisco.com/warp/customer/110/cp-p.html

Best Regards,

Thanks a lot