Link to home
Start Free TrialLog in
Avatar of NytroZ
NytroZFlag for United States of America

asked on

Allow incoming PPTP to Juniper NS5GT

I need to allow PPTP traffic through the Juniper firewall to a Microsoft RRAS server.

Public VPN IP is 1.1.1.1
private IP is 10.1.1.10

Can someone help configure teh firewall to pass teh PPTP traffic?

I tried to open port 1723 and create a MIP to the private IP but this is not working.
ASKER CERTIFIED SOLUTION
Avatar of Sanga Collins
Sanga Collins
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
A "port" does not exist for GRE (protocol 47) - that protocol does not know of the concept of ports. A port restriction is useless, and maybe even leads to failure. I can see Juniper recommends that, but I cannot tell why that port restriction should apply at all.

I would not set up MIP for this, as this reserves a IP address completely and solely to get redirected to a single machine. VIP is much more useful, as it allows a per-port definition of (internal) target IPs.
BTW GRE is a pre defined service in screenOS 6 and greater

"GRE       IP (47) any       Generic Routing Encapsulation       60"

I can not speak on how or why it works, all i know is without it I was not able to setup the VPN server successfully.
Yes, one should forward GRE traffic the same as PPTP. It can work without, but will not most of the time.