[Date Prev][Date Next][Thread Prev][Thread Next][Thread Index]

Re: [fw1-gurus] Clients behind a Enforcement Module can't not establisha PPTP VPN connection to Win2K3 VPN server behind other Enforcement Module



Just for the sake of clarification, any/any will not work. You need specific source/dest rules for this with pptp specified as the service.

shinbe@xxxxxxxxx wrote:
Hi Juan,
I created a "automatic" static-nat for my PC
Each firewall was run with "any any any accept" rule I will try to update latest hotfix and tell you the result
Thank you

-----Original Message-----
From: Juan Concepcion [mailto:juan.concepcion@xxxxxxxxxxx] Sent: Tuesday, December 28, 2004 9:27 PM
To: shinbe@xxxxxxxxx
Cc: fw1-gurus@xxxxxxxxxxxxxxxxxx
Subject: Re: [fw1-gurus] Clients behind a Enforcement Module can't not
establisha PPTP VPN connection to Win2K3 VPN server behind other Enforcement
Module

First pptp will not work with hide-nat. Secondly when you attempted to do it via static-nat did you create 2 rules one inbound the other outbound to the static nat you assigned your pc for specific pptp protocols, where "any" will not work?

Juan

shinbe@xxxxxxxxx wrote:

Hi gurus,
My customer has a Win2k3 VPN server that static-nated through a NG FP3
firewall.
My PC is hide-nated behind a NG R55 firewall. It can't establish a PPTP

VPN

connection to the VPN Server
The connection stop at "verify username and password" step. Security

policy

was "any any accept" on both firewalls
I've tried static-nated my PC but nothing better.
As sk12234, it should be OK. I don't know why.
Have you got any hints for me
Thank you




---------------------------------------------------------------------
FireWall-1 Gurus Mailing List (http://www.phoneboy.com/gurus)
To unsubscribe, mailto:fw1-gurus-unsubscribe@xxxxxxxxxxxxxxxxxx
For additional commands, mailto:fw1-gurus-help@xxxxxxxxxxxxxxxxxx







---------------------------------------------------------------------
FireWall-1 Gurus Mailing List (http://www.phoneboy.com/gurus)
To unsubscribe, mailto:fw1-gurus-unsubscribe@xxxxxxxxxxxxxxxxxx
For additional commands, mailto:fw1-gurus-help@xxxxxxxxxxxxxxxxxx