Your clients are connecting, but the PIX is trying to do network address translation on the packets instead of using the actual IP address given to your remote connections.
Add a NAT statement to the PIX so that the PIX does not do any translation on the PPTP client's traffic.
First, I would recommend changing your local pool "mypool" to a different subnet. Otherwise, you will run into additional configuration requiring you to subnet out the bits in the access lists for the subnet masks pertaining to your PPTP clients (the .220-.240 addresses) as they are on the same subnet as your internal network. Using a different subnet makes for an easier config...but it's not required.
For my example, change your "mypool" to "192.168.254.1-192.168.254.10"
Also, the PIX-501 only supports 10 concurrent VPN peers...handing out 21 addresses in your ip pool is not needed.
Create an access-list that defines traffic that does not to be NAT'd.
access-list nonat permit ip 192.168.1.0 255.255.255.0 192.168.254.0 255.255.255.0
Now, apply the new access-list to a "no nat" statement for the PIX
nat (inside) 0 access-list nonat
This tell the PIX not to NAT any traffic matching the "nonat" access list. The use of "0" with the nat statement is what actually tells the PIX not to NAT.
Since you are using the "sysopt connection permit-ipsec" command, all pptp traffic bypasses access-lists and will be permited.
DocumentationCode download linksGoalRequirementLimitationsSupported ISR
and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationConfigure one of the connectivity
options to access the Cisco IMC from the n...
Firepower Threat Defense (NGFWv) on UCS E-series - Transparent Mode in
HA DocumentationCode download linksGoalRequirementLimitationsSupported
ISR and UCS-E ModelSupported ISRG2 and UCS-E Blades:Supported ISR4K and
UCS-E Blades:Step by Step ConfigurationCo...
Question I am currently unable to specify "crypto keyring" command when
configuring VPN connection on my cisco 2901 router. The following
licenses have been activated on my router :