Avatar of Bill Warren
Bill Warren
Flag for United States of America asked on

VPN from ipad to Cisco PIX-501

Is is possible to VPN to a PIX-501 from my ipad... in the ipsec config on the ipad it is asking me for Server, account, password, Group Name, and Secret... however with my VPN client I am just used to needing a server address, username and password is it possible to connect to the PIX?
CiscoVPNApple Networking

Avatar of undefined
Last Comment
Bill Warren

8/22/2022 - Mon
Adrian Cantrill

have you tried just entering servername username and password and attempting a connection ?
Bill Warren

ASKER
Yeah it says i need to enter a secret... I have no secret to add... if I just add anything it does accept it
Adrian Cantrill

what type of VPN have you configured on the PIX ? what protocol etc. Secrets are generally used for site2site VPN links .. odd why the ipad is prompting for that.
All of life is about relationships, and EE has made a viirtual community a real community. It lifts everyone's boat
William Peck
Bill Warren

ASKER
ipsec
Adrian Cantrill

and you have configured it as a remote access VPN and not site to site ?
Bill Warren

ASKER
I have it working with both VPN clients and Site to Site VPN there is no "Secret" with the site to site either
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.
kingdingathing

Straight from the cisco site:

"The Cisco ASA 5500 series and PIX Firewalls work with the Cisco VPN Client on the iPhone. We highly recommend the 8.0(x) software release or later, but you can also use the 7.2(x) software."

http://www.cisco.com/en/US/docs/security/asa/compatibility/asa-vpn-compatibility.html

It mentions that at the bottom of the page...

Basically its preferred if your PIX-501 has 8.0 or later firmware installed. Then all things should work as its supposed to.
ASKER CERTIFIED SOLUTION
gavving

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
Bill Warren

ASKER
I decided to try to VPN to my Windows Server which I did connect the first time and after that I cannot through the PIX. However i can connect locally to the server. I have opended up port 1736. I just find it odd that I connected once through the WAN but cannot connect again.
gavving

To allow inbound MS PPTP you have to allow inbound port 1723, and GRE protocol to a static one-to-one NATed address for your server.  

access-list acl-outside permit tcp any host 45.2.2.2 eq 1723
access-list acl-outside permit gre any host 45.2.2.2

where 45.2.2.2 is your NATed IP address of your windows server.
I started with Experts Exchange in 2004 and it's been a mainstay of my professional computing life since. It helped me launch a career as a programmer / Oracle data analyst
William Peck
Bill Warren

ASKER
Thanks those lines did the trick!