troubleshooting Question

Netscreen 5GT Outgoing PPTP

Avatar of zimboman
zimbomanFlag for New Zealand asked on
Software Firewalls
7 Comments1 Solution1868 ViewsLast Modified:
Hi all,
I know this has been discussed ad nauseum, but I am still not able to get this to work. Please could I trouble you all for some clarification...

I have a network, protected by a 5GT. I have ony ONE static, external IP address, which has been assigned to my untrust interface. At the moment, I have an outgoing any any PPTP rule. Funny thing is, there is one pptp server, which I can connect to without any problems. The one that I need to though, and others, halts when verifying username and password. I basically understand that GRE is not being routed back through the firewall, I guess. (it would help if the one I used to test didn't actually work)

I have read other posts advising to set up DIPS. Well, I have only one ext IP, so that is not an option for me (I think?) I don't mind the fact that I will only be able to have one connection out at a time, it is just for testing a project, which is due soon.

I tried to set up a dip, using a range that only included my one address, ie. 1.1.1.1 ~ 1.1.1.1 - but that didn't work. I got an ###invalid dip parameter message. So I guess I am on the wrong track there.

I also read about using MIPS. Well I tried to create a MIP, with a mapped ip - same as untrust /static external IP, to the one host IP I wanted to test from, and I got an error that one of the ip's in the suggested range was in use... So THAT won't work either...

Sorry all, but I am tearing my hair out - surely this shouldn't be this difficult?

Thank you in advance for your help...

ZM
ASKER CERTIFIED SOLUTION
rsivanandan

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 1 Answer and 7 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 1 Answer and 7 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros