RE: Cisco Pix 535

  • From: "Lian-Wee LOO" <lwloo@xxxxxxx>
  • To: "'[ISAserver.org Discussion List]'" <isalist@xxxxxxxxxxxxx>
  • Date: Tue, 6 Apr 2004 10:44:02 +0800

My ISA are working fine, I can connect to my ISA VPN using other dialup,
just that the one behind CISCO PIX is not working :-( Please give detailed
config what can I do in Cisco PIX to allow VPN connection. Thanks.

 

best regards,

lwloo 2k'3

 

  _____  

From: Federico Muller, TKL [mailto:fmuller@xxxxxxxxxx] 
Sent: Tuesday, April 06, 2004 4:19 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Cisco Pix 535

 

http://www.ISAserver.org

The lines that you need in your cisco pix to forwards vpn packets for your
external card of your isa server is:

 

static (inside,outside) "External IP from PIX"  "External IP ISA netmask
255.255.255.255 

conduit permit gre host "External IP PIX" any

conduit permit tcp host  "External IP PIX" eq 1723 any

conduit permit udp host  "External IP PIX" eq 1723 any

 

ex: static (inside,outside) xx..xx.xx.xx yy.yy.yy.yy netmask 255.255.255.255


conduit permit gre host xx..xx.xx.xx any

conduit permit tcp host xx..xx.xx.xx eq 1723 any

conduit permit udp host xx..xx.xx.xx eq 1723 any

 

you also can use access list for permit the traffic, is the same to use
conduits.

 

 

 

Federico Muller

MOS, MCSA, MCSE, MCT, CCNA, Security+

Training & Consulting Manager

TeKnowlogic Dominicana

Tel.: (809) 683-6646 Fax: (809) 683-6608

  _____  

From: Lian-Wee LOO [mailto:lwloo@xxxxxxx] 
Sent: Monday, April 05, 2004 11:02 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Cisco Pix 535

 

http://www.ISAserver.org

I am not sure, I don't think they will change. Anyway to resolve? What are
the port need to be open in order for me to connect to ISA VPN server? It
always stuck at the user authentication part, should be error 721. Please
advice. Thank you.

 

best regards,

lwloo 2k'3

 

  _____  

From: Thomas W Shinder [mailto:tshinder@xxxxxxxxxxx] 
Sent: Monday, April 05, 2004 8:29 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Cisco Pix 535

 

http://www.ISAserver.org

Hi Lian,

 

Sounds like the PIX is misconfigured, which is a common problem.

 

They might want to consider upgrading the PIX to ISA 2004.

 

HTH,

Tom

 

  _____  

From: Lian-Wee LOO [mailto:lwloo@xxxxxxx] 
Sent: Monday, April 05, 2004 4:47 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] Cisco Pix 535
Importance: High

http://www.ISAserver.org

I am behind Cisco PIX 535 and tried to connect to my office VPN which is on
MS ISA. It always stuck at the verifying user/password (Error 721 if I am
not mistaken). Any idea? Please help.

 

best regards,

lwloo 2k'3

 

 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
tshinder@xxxxxxxxxxxxxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub')
------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
lwloo@xxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub') 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
fmuller@xxxxxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub') 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
lwloo@xxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub') 

Other related posts: