PPTP connection terminating on a PIX....Having routing issues with Internal networks.

Posted on 2005-04-29
Last Modified: 2010-04-12
I have a PIX 501 with configuration  listed below. I am able to get connected and able to connect to devices on the same network segment as the inside interface but there is another internal network of that I also need my PPTP VPN client to access. I am able to ping this network when I SSH to the pix and also from clients that are in the network. The only client that are not able to connect to this netowrk is client that terminate to the PIX via a PPTP connection. Thank in advance.

PIX Version 6.3(4)
interface ethernet0 auto
interface ethernet1 10full
nameif ethernet0 outside security0
nameif ethernet1 inside security100
enable password lkdjflkjsdkfnklsdf encrypted
passwd kjdshfkjshdfn encrypted
hostname pix
fixup protocol dns maximum-length 512
fixup protocol ftp 21
fixup protocol h323 h225 1720
fixup protocol h323 ras 1718-1719
fixup protocol http 80
fixup protocol ils 389
fixup protocol pptp 1723
fixup protocol rsh 514
fixup protocol rtsp 554
fixup protocol sip 5060
fixup protocol sip udp 5060
fixup protocol skinny 2000
fixup protocol smtp 25
fixup protocol sqlnet 1521
fixup protocol tftp 69
access-list 100 permit icmp any any
access-list 100 permit ip
access-list 100 permit ip
access-list 102 permit ip any any
pager lines 24
logging buffered informational
mtu outside 1500
mtu inside 1500
ip address outside x.x.x.x
ip address inside
ip audit info action alarm
ip audit attack action alarm
ip local pool remote mask
pdm history enable
arp timeout 14400
global (outside) 1 interface
nat (inside) 0 access-list 100
nat (inside) 1 0 0
access-group 102 in interface outside
route outside x.x.x.x
route inside 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00
timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00
timeout uauth 0:05:00 absolute
aaa-server TACACS+ protocol tacacs+
aaa-server TACACS+ max-failed-attempts 3
aaa-server TACACS+ deadtime 10
aaa-server RADIUS protocol radius
aaa-server RADIUS max-failed-attempts 3
aaa-server RADIUS deadtime 10
aaa-server LOCAL protocol local
no snmp-server location
no snmp-server contact
snmp-server community public
no snmp-server enable traps
floodguard enable
telnet inside
telnet timeout 5
ssh outside
ssh timeout 5
console timeout 0
vpdn group corebts accept dialin pptp
vpdn group corebts ppp authentication pap
vpdn group corebts ppp authentication chap
vpdn group corebts ppp authentication mschap
vpdn group corebts ppp encryption mppe 40
vpdn group corebts client configuration address local remote
vpdn group corebts pptp echo 60
vpdn group corebts client authentication local
vpdn username ******** password *********
vpdn enable outside
terminal width 80
Question by:shenanigan
    LVL 6

    Accepted Solution

    you have a route for inside:
    >route inside 1    --> that covers, okay.
    assuming that knows the route back to (double check), but your no-nat acl doesn't make sense:
    >access-list 100 permit ip ---same source and dest or typo?
    >access-list 100 permit ip --- doesn't cover
    try this:
    access-list 100 permit ip
    access-list 100 permit ip
    LVL 79

    Expert Comment

    Magico found the same thing I did, so you're on the right track.
    Make sure the client has "use default gateway on remote network" checked. You might not like the result.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How to improve team productivity

    Quip adds documents, spreadsheets, and tasklists to your Slack experience
    - Elevate ideas to Quip docs
    - Share Quip docs in Slack
    - Get notified of changes to your docs
    - Available on iOS/Android/Desktop/Web
    - Online/Offline

    Suggested Solutions

    Title # Comments Views Activity
    VPN server setup 5 56
    OPenvpn connect for my Macbook pro laptop 5 44
    ACL per VPN User 12 96
    Sonicwall SOHO SSL-VPN no LAN Access 5 40
    Using Windows 2008 RRAS, I was able to successfully VPN into the network, but I was having problems restricting my test user from accessing certain things on the network.  I used Google in order to try to find out how to stop people from accessing c…
    Some of you may have heard that SonicWALL has finally released an app for iOS devices giving us long awaited connectivity for our iPhone's, iPod's, and iPad's. This guide is just a quick rundown on how to get up and running quickly using the app. …
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    761 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now