Question

Need help on Pix Urgent

Asked by: rockyt

Hi all,

    I have configured VPDN on my pix thru pptp, and i want that those user's who connect to thru vpn they can also access internet or browse the website. can u guys plz help me out. asap on this regds,

Regds,
Rankit

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2006-10-01 at 20:52:06ID22009373
Tags

pix

,

pptp

Topics

Miscellaneous Networking

,

Networking Hardware Firewalls

,

IPSec Security Protocol

Participating Experts
2
Points
125
Comments
21

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Enable PPTP on PIX
    Hi, Appreciate if anyone could provide me with instructions on how to enable the PPTP in the PIX for VPN access? I have setup a WinXP Prof VPN Server in my LAN but couldnt figure out how to make it possible for remote clients to connect to it. Currently running a Cisco PIX...
  2. PIX 501 PPTP VPN Config
    Would someone mind checking over my config? I can't seem to get a PPTP VPN session running. This is my home/test PIX and I'm trying to connect from work. Here's what I've got: 6.3(3) nat (inside) 0 access-list 109 nat (inside) 1 0.0.0.0 0.0.0.0 0 0 access-list 109 permit ...
  3. How can I setup the PPTP VPN in Cisco PIX?
    I using the following command to create the PPTP VPN: - ip local pool PPTP_POOL 10.128.2.220-10.128.2.240 - vpdn group HK_PPTP accept dialin pptp - vpdn group HK_PPTP ppp authentication pap - vpdn group HK_PPTP ppp authentication chap - vpdn group HK_PPTP ppp authentication m...
  4. Pix 501 Version 6.3(5) - Can not enable vpdn on t…
    Hi all, I get the message "Can not enable vpdn on the same interface as PPPoE." Pix is used for internet access. Setup VPN (PPTP) using VPN wizard but cannot enable outside port due to this message. Can you advise. Thanks

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: photograffitiPosted on 2006-10-01 at 20:58:55ID: 17640895

Are you trying to force their Internet traffic to go through the VPN tunnel too? Or do you just want company traffic to go through the VPN but regular web/internet traffic to go out normally? If it is the latter, then on the user's local machine you can make some changes to their PPTP VPN settings to allow this.
Go to Start Menu and then to the Network connections. Go to the properties for the VPN connection to your company. Choose the Networking Tab. Choose Internet Protocol and Properties. Go to Advanced and then uncheck the 'Use default gateway' box under the General tab.
That should do it. Good luck.

 

by: rockytPosted on 2006-10-01 at 22:05:17ID: 17641057

Hi forgoted to leave the config here is the config plz let me know wut shud i do, also my pdm has stoped working and giving me error.

PIX Version 6.2(2)
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password RgJtt01a0tCQUeNg encrypted
passwd RgJtt01a0tCQUeNg encrypted
hostname pixfirewall
domain-name lotusexim.com
fixup protocol ftp 21
fixup protocol http 80
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol ils 389
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol sip 5060
fixup protocol skinny 2000
names
name 208.210.221.70 manager
name 192.168.10.100 LOTUSFAX
name 192.168.10.99 IBMMAIN
name 192.168.10.98 LOTUS-CITRIX
name 192.168.10.23 rankit
name 192.168.10.101 ibmsql
access-list inside_access_in permit tcp any any
access-list 101 permit ip 192.168.10.0 255.255.255.0 10.1.1.0 255.255.255.0
access-list 200 permit icmp any any echo-reply
access-list 200 permit icmp any any unreachable
access-list 200 permit icmp any any time-exceeded
access-list 200 permit tcp any host 67.154.78.165 eq pcanywhere-data
access-list 200 permit udp any host 67.154.78.165 eq pcanywhere-status
access-list 200 permit tcp any host 67.154.78.164 eq pcanywhere-data
access-list 200 permit udp any host 67.154.78.164 eq pcanywhere-status
access-list 200 permit tcp host 203.101.126.81 host 67.154.78.171 eq citrix-ica
access-list 200 permit tcp any host 67.154.78.166 eq www
access-list 200 permit tcp any host 67.154.78.166 eq https
access-list 200 permit tcp any host 67.154.78.164 eq ftp
access-list 200 permit tcp any host 67.154.78.171 eq citrix-ica
access-list 200 permit tcp host 64.178.39.18 host 67.154.78.171
access-list 200 permit tcp any host 67.154.78.164 eq www
access-list 200 permit tcp any host 67.154.78.164 eq 3389
access-list 200 permit tcp any host 67.154.78.166 eq 5800
access-list 200 permit tcp any host 67.154.78.166 eq 5900
access-list 200 permit tcp any host 67.154.78.164 eq 8081
access-list 200 permit tcp any host 67.154.78.164 eq 5900
access-list 200 permit tcp any host 67.154.78.164 eq https
access-list 200 permit tcp any host 67.154.78.164 eq 8098
pager lines 24
logging on
interface ethernet0 10baset
interface ethernet1 10full
mtu outside 1500
mtu inside 1500
ip address outside 67.154.78.162 255.255.255.224
ip address inside 192.168.10.1 255.255.255.0
ip verify reverse-path interface outside
ip audit info action alarm
ip audit attack action alarm
ip local pool pptp-pool 10.1.1.2-10.1.1.25
pdm location IBMMAIN 255.255.255.255 inside
pdm location LOTUSFAX 255.255.255.255 inside
pdm location rankit 255.255.255.255 inside
pdm location LOTUS-CITRIX 255.255.255.255 inside
pdm location 10.1.1.0 255.255.255.0 outside
pdm location 61.95.201.73 255.255.255.255 outside
pdm location 67.154.146.74 255.255.255.255 outside
pdm location 203.101.126.65 255.255.255.255 outside
pdm location 203.101.126.81 255.255.255.255 outside
pdm location 206.126.178.156 255.255.255.255 outside
pdm location 207.38.252.225 255.255.255.255 outside
pdm location manager 255.255.255.255 outside
pdm location 67.154.78.166 255.255.255.255 outside
pdm location 64.178.39.18 255.255.255.255 outside
pdm location ibmsql 255.255.255.255 inside
pdm location 10.1.1.2 255.255.255.255 inside
no pdm history enable
arp timeout 14400
global (outside) 1 67.154.78.168-67.154.78.177 netmask 255.255.255.224
global (outside) 1 67.154.78.178
nat (inside) 0 access-list 101
nat (inside) 1 10.1.1.0 10.1.1.25 0 0
nat (inside) 1 0.0.0.0 0.0.0.0 0 0
static (inside,outside) 67.154.78.165 LOTUSFAX netmask 255.255.255.255 0 0
static (inside,outside) 67.154.78.164 IBMMAIN netmask 255.255.255.255 0 0
static (inside,outside) 67.154.78.171 LOTUS-CITRIX netmask 255.255.255.255 0 0
static (inside,outside) 67.154.78.166 ibmsql netmask 255.255.255.255 0 0
access-group 200 in interface outside
route outside 0.0.0.0 0.0.0.0 67.154.78.161 1
timeout xlate 0:05:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si
p 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server RADIUS protocol radius
aaa-server LOCAL protocol local
http server enable
http 206.126.178.156 255.255.255.255 outside
http 0.0.0.0 0.0.0.0 inside
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
sysopt connection permit-ipsec
sysopt connection permit-pptp
no sysopt route dnat
crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac
crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA
crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map
crypto map outside_map interface outside
isakmp enable outside
isakmp policy 20 authentication pre-share
isakmp policy 20 encryption 3des
isakmp policy 20 hash sha
isakmp policy 20 group 2
isakmp policy 20 lifetime 86400
telnet manager 255.255.255.255 outside
telnet 192.168.10.0 255.255.255.0 inside
telnet timeout 5
ssh manager 255.255.255.255 outside
ssh 192.168.10.0 255.255.255.0 inside
ssh timeout 5
vpdn group 1 accept dialin pptp
vpdn group 1 ppp authentication pap
vpdn group 1 ppp authentication chap
vpdn group 1 ppp authentication mschap
vpdn group 1 ppp encryption mppe auto
vpdn group 1 client configuration address local pptp-pool
vpdn group 1 client configuration dns 209.216.241.10 216.99.225.31
vpdn group 1 client configuration wins IBMMAIN LOTUSFAX
vpdn group 1 pptp echo 60
vpdn group 1 client authentication local
vpdn username perfectvpn password *********
vpdn username elegantvpn password *********
vpdn username gmkconsult password *********
vpdn username bestvpn password *********
vpdn username rankitt password *********
vpdn username lotusexim password *********
vpdn username rankit password *********
vpdn enable outside
terminal width 80

 

by: rockytPosted on 2006-10-01 at 22:06:52ID: 17641059

Hi photograffiti.. i tried doing that also but dint worked out with me.. can u suggest me looking at the pix config file and let me know if anything to be done in pix.. i really need to solve this asap. thanks for your quick reply

 

by: rockytPosted on 2006-10-01 at 22:15:48ID: 17641071

ya i want that all the clients who get connected thru vpn, their traffic for internet shud go thru vpn it self. Means they can also browse all the websites. as of now they can only access our internal user, so when they get connected to vpn they cannot access yahoo or hotmail. so i have pasted the configuration and let me know if i have to do something on pix , coz i m new in pix and dont have much knowledge about it. thanks for your help

 

by: photograffitiPosted on 2006-10-01 at 22:19:42ID: 17641077

This is not possible with the version of PIX OS that you are running. For that version, traffic going in an interface can't turn around and go right back out the same interface without actually going through the entire PIX. Since you're VPN traffic is coming in through the outside interface it would have to turn right around and leave that interface to get to the Internet. This won't work.
I believe version 7.0 and higher allows this type of traffic flow.

 

by: rockytPosted on 2006-10-01 at 22:23:13ID: 17641079

so u mean to say nothing can be done in that case.. wut if we install proxy server in the win2k3 server and then give the proxy ip on the client's pc, will it work ?

 

by: photograffitiPosted on 2006-10-01 at 22:31:22ID: 17641101

Yes, that will work. The VPN traffic in that case will be flowing all the way through the PIX (to the proxy server) and then back out via the proxy server. If you don't care that all traffic should have to go through the VPN then you can do a split tunnel type of setup with web traffic going out their local connections from home/hotel.

 

by: rockytPosted on 2006-10-01 at 22:35:14ID: 17641107

so u mean in that the existing internal user's will not be affected while creating split tunnel for that. can u plz let me know who shud i configure split tunnel for the same. to be very frank, my existing manager left the organisation without any handover and i am not too techy in pix. and now its totaly on me and i m in soup. i really appreciate your help.

 

by: photograffitiPosted on 2006-10-01 at 22:44:11ID: 17641124

Sorry to hear about your situation. As for the split tunneling, what I originally posted should have worked. Your configuration looks fine and should work with that little tweak on the PC.
Also, I would suggest you contact an admin and have them remove the outside IP address from your config as well as any NAT addresses. You don't want to open yourself up to any hacking.

 

by: rockytPosted on 2006-10-02 at 06:03:59ID: 17642987

hi, can anyone tell me whether pix 6.2 version support split tunnel so that i can configure it on the same.

 

by: photograffitiPosted on 2006-10-02 at 08:40:39ID: 17644254

The PIX supports split-tunneling but only for the Cisco VPN client (IPSec). To get split-tunneling to work on the Microsoft PPTP client the changes have to all be done on the client side, not the PIX. One additional thing that might be needed on your client is to add a route manually. This isn't always needed but can help.
When you connect via the PPTP client you should get an IP address assigned to the new PPTP adapter. Find out what it is by going to the Command Prompt and typing 'ipconfig'. When you find out what IP address it is then type in the following - 'route add 10.1.1.0 mask 255.255.255.0 w.x.y.z' - where w.x.y.z is the IP address of your adapter. Note that you are pointing to your own IP address and not some other default gateway.
Let me know how it goes.

 

by: rockytPosted on 2006-10-02 at 11:46:20ID: 17645737

hi thanks a lot dude.. u really helping me.. from your comment, i understand that when i get the ip address 10.1.1.2 i have to go to pix and give the manual route, correct.

 

by: rockytPosted on 2006-10-02 at 11:58:53ID: 17645829

hi i tried adding route add command but no success on my computer , i mean i connected my laptop thru vpn pptp client and got the default gateway. and tried to add but still no sucess.. ? this is really driving me crazy.. i think i m going to die now :-)

 

by: photograffitiPosted on 2006-10-02 at 12:02:43ID: 17645860

Did you try to add or were you successful adding the route, but it still didn't help? Did you also uncheck the Use Default Gateway part that I mentioned in my original post? You're supposed to do both.

 

by: rockytPosted on 2006-10-02 at 12:07:33ID: 17645907

yes i tried to add the route successfully, but the problem is when i tried to uncheck the default gateway from the part mentioned it takes my internet thing. and over here in UAE some of the sites are blocked so i cannot access my company's website due to that, thats the only reason i want my traffic shud go thru U.S firewall. as we have some user's in dubai and over there we cannot access sites thru IP address. or some of the sites are banned as they are using content filtering thats the reason i want my traffic shud go from pix. or u.s proxy.

 

by: photograffitiPosted on 2006-10-02 at 12:48:50ID: 17646290

Well, we're back to my other post then. If you want split-tunneling then that's what you have right now. But since you don't want Internet traffic to go out your local connection then you DON'T want split tunneling. In that case you will have to get a proxy server or update your firewall because as it is right now that won't work.

 

by: rockytPosted on 2006-10-02 at 21:39:58ID: 17649234

ok so no other option except updating the firewall rite..

 

by: photograffitiPosted on 2006-10-02 at 21:49:39ID: 17649265

Well you can update the firewall or use the proxy option. And if you want to update the firewall you might or might not be able to depending on the hardware you have. If you have a PIX 501 or 506 then you are SOL. You need at least a PIX 515 to get to PIX 7.0 code.

 

by: rockytPosted on 2006-10-02 at 22:26:32ID: 17649376

ok dude can u tell me one thing.. i have terminal server installed on my server which works on https://ipaddress:8098 and in uae its blocked. with port. now i want to have a port translation or NAT thru which my user's in uae can access that thru default port. means. they just have to type the http://ipaddress can u suggest me what shud i do for the same. in the pix how will pix translate the port.

 

by: riteheerPosted on 2006-10-31 at 19:25:07ID: 17847501

No comment has been added to this question in more than 21 days, so it is now classified as abandoned.
I will leave the following recommendation for this question in the Cleanup topic area:
"Accept photograffiti's comments as an answer"


Any objections should be posted here in the next 4 days. After that time, the question will be closed.

Thank you
Riteheer
EE Cleanup Volunteer

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...