[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now


How can I open IP protocol 47 (GRE) in PIX firewall?

Posted on 2007-08-07
Medium Priority
Last Modified: 2013-11-16
Hi Expert,
I'm facing trouble related to establish VPN between our network and remote company, as trouble shooting the remote side inform me that Generic Route Encapsulation (GRE) protocol not open in our firewall, and needed to check and open it.
How can I check the opened IP protocol, and how can I open this GRE protocol , protocol # 47 ?

Thanks ,,,
Question by:Mesfer
LVL 29

Accepted Solution

Alan Huseyin Kayahan earned 1000 total points
ID: 19652872
       Hi Mesfer
                fixup protocol pptp 1723
                 Above should fix it, if it does not, then
access-list outside_access_in permit tcp any host <public IP of VPN server> eq pptp
access-list outside_access_in permit gre any host <public IP of VPN server>
access-group outside_access_in in interface outside

LVL 79

Assisted Solution

lrmoore earned 1000 total points
ID: 19653129
The fixup protocol pptp 1723 should fix it for PIX 6.3
For ASA and PIX 7.0 use inspect
hostname(config)# class-map pptp-port
hostname(config-cmap)# match port tcp eq 1723
hostname(config-cmap)# exit
hostname(config)# policy-map pptp_policy
hostname(config-pmap)# class pptp-port
hostname(config-pmap-c)# inspect pptp
hostname(config-pmap-c)# exit
hostname(config)# service-policy pptp_policy interface outside

Expert Comment

ID: 20119935
Forced accept.

EE Admin

Expert Comment

ID: 25914012
Solution from lrmoore worked for me! Thanx!

Featured Post

 The Evil-ution of Network Security Threats

What are the hacks that forever changed the security industry? To answer that question, we created an exciting new eBook that takes you on a trip through hacking history. It explores the top hacks from the 80s to 2010s, why they mattered, and how the security industry responded.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses
Course of the Month19 days, 9 hours left to enroll

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question