Windows 2003 PPTP VPN through PIX 506e
Posted on 2006-06-07
I have a PIX 506e firewall that appears to be blocking our VPN connections despite having the appropriate ports opened.
I'm able to connect to the VPN through the LAN, but am unable to connect from the outside. When I attempt to connect, I get an error 678. Here is the running-config lines for the VPN pass-through:
fixup protocol pptp 1723
access-list 101 permit tcp any host xxx.xxx.xxx.xxx eq pptp
access-list 101 permit gre any host xxx.xxx.xxx.xxx
static (inside,outside) tcp xxx.xxx.xxx.xxx pptp yyy.yyy.yyy.yyy pptp netmask 255.255.255.255 0 0
access-group 101 in interface outside
Am I missing something? Is the PIX 506e capable of handling this? Also, I have previously used the Cisco 506e built-in VPN client but have since added 30 additional VPN users through various sales sites. Do I need to remove the Cisco VPN config first? Is that in any way hindering the PPTP traffic to the Windows 2003 server?
Thanks in advance,