PIX, PPTP and Internet access for PPTP users...

PIX, PPTP and Internet access for PPTP users...

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
PIX, PPTP and Internet access for PPTP users... Michael J. Pelletier 03-15-2005
Posted by Michael J. Pelletier on March 15, 2005, 7:32 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I have a PIX 525e that is my company's firewall and VPN (for remote site
connectivity). Today, I configured it to do PPTP for some of our employees
hoping to get away from the MS PPTP server. I noticed today while testing
the configuration that I could not get to the Internet when using PPTP.
Now, I know I can configure it to do "split tunneling" however, I do not
wish to do split tunneling (long story, not my choice).

I read a post from some news group that the PIX will not allow you to route
out the same interface the encrypted packet came in on. In other words the
"outside" interface is the PPTP tunnel end point and I can not route (the
client using PPTP) the packet out into the Internet (also the outside
interface). I can only use it to connect to internal PCs.

Is this true?
Is there any work around?
If I used a router for PPTP could I get around this?

P.S. I know PPTP sucks (that also is not my choice)

Michael


Posted by William L. Sun on March 15, 2005, 8:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
It is true that "PIX will not allow you to route out the same interface the
encrypted packet came in on". The only thing you can do is to let the VPN
client to use Proxy server.

> Hello,
>
> I have a PIX 525e that is my company's firewall and VPN (for remote site
> connectivity). Today, I configured it to do PPTP for some of our employees
> hoping to get away from the MS PPTP server. I noticed today while testing
> the configuration that I could not get to the Internet when using PPTP.
> Now, I know I can configure it to do "split tunneling" however, I do not
> wish to do split tunneling (long story, not my choice).
>
> I read a post from some news group that the PIX will not allow you to
route
> out the same interface the encrypted packet came in on. In other words the
> "outside" interface is the PPTP tunnel end point and I can not route (the
> client using PPTP) the packet out into the Internet (also the outside
> interface). I can only use it to connect to internal PCs.
>
> Is this true?
> Is there any work around?
> If I used a router for PPTP could I get around this?
>
> P.S. I know PPTP sucks (that also is not my choice)
>
> Michael




Similar ThreadsPosted
Remote access vpn using PPTP June 19, 2006, 8:50 pm
Users can't access the internet December 6, 2004, 3:33 pm
PPTP to Watchguard X15 May 2, 2006, 12:14 pm
Watchguard X500 PPtP July 28, 2005, 6:26 pm
Using VPN (PPTP) behind Windows XP Firewall November 3, 2005, 4:17 am
PPTP/GRE Open Port on firewall November 15, 2004, 2:58 am
Strange problem when using PPTP VPN through Cisco PIX October 21, 2005, 3:42 am
PPTP over Zyxel NAT and win2003 server January 17, 2007, 8:57 am
iptables + pptp + special case March 13, 2007, 9:25 am
Watchguard Firebox 2 (PPTP and GRE Pass Through) March 20, 2007, 1:28 pm

The site map in XML format XML site map

Contact Us | Privacy Policy