Solved

Configuring Microsoft VPN via Cisco PIX (ver. 5.1(4)) - continued

Posted on 2003-11-12
7
614 Views
Last Modified: 2013-11-16
td_miles was alot of help on this issue (see link below)

http://www.experts-exchange.com/Security/Firewalls/Q_20793766.html#9726724

But I'm still having issues - getting a 721 error when connecting from the client computer. Using this:

access-list acl-out permit gre any host 216.xx.xx.xx
access-list acl-out permit tcp any host 216.xx.xx.xx

static (inside,outside) 216.xx.xx.xx 192.168.xx.xx netmask 255.255.255.255 0

access-group acl-out in interface outside

It worked great, but shut down all incoming access on everything else and using this:

conduit permit esp any host 216.x.x.x
conduit permit udp any eq isakmp host 216.x.x.x
conduit permit gre any host 216.x.x.x

Isn't working for me. I changed the "any" in the above to host xx.xx.xx.xx the client IP address, and still get a 721 error from the VPN client connection. Any ideas?
0
Comment
Question by:welshiv
  • 4
7 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 9735461
>216.xx.xx.xx
Is this the same IP address as your outside interface?

Try changing this:
>access-list acl-out permit tcp any host 216.xx.xx.xx

to this to be port-specific. This will keep from killing all your access:
access-list acl-out permit tcp any 1723 host 216.xx.xx.xx 1723
 
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 9735492
Wait, I just read the other link.
You are using conduits, not acls...
you should use the private IP of the host:

conduit permit esp host 192.168.x.x any
conduit permit udp eq isakmp host 192.168.x.x any
conduit permit gre host 192.168.x.x any

0
 

Author Comment

by:welshiv
ID: 9735656
I did use the private IP of the host - didn't work
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 79

Accepted Solution

by:
lrmoore earned 250 total points
ID: 9735709
DOH!
Of course..
you need tcp 1723...not esp or isamkp for PPTP.

conduit permit tcp host 192.168.x.x  eq 1723 any


0
 
LVL 79

Expert Comment

by:lrmoore
ID: 9774431
Are you still working on this? Can you update us with your status?

Thanks!
0
 
LVL 23

Expert Comment

by:Tim Holman
ID: 10976439
No comment has been added to this question in more than 21 days, so it is now classified as abandoned..
I will leave the following recommendation for this question in the Cleanup topic area:

--> Accept: lrmoore

Any objections should be posted here in the next 4 days. After that time, the question will be closed.

tim_holman
EE Cleanup Volunteer
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
When you create an app prototype with Adobe XD, you can insert system screens -- sharing or Control Center, for example -- with just a few clicks. This video shows you how. You can take the full course on Experts Exchange at http://bit.ly/XDcourse.
This video explains how to create simple products associated to Magento configurable product and offers fast way of their generation with Store Manager for Magento tool.

758 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now