RE: Cisco Pix 535

  • From: "Federico Muller, TKL" <fmuller@xxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 5 Apr 2004 16:18:49 -0400

The lines that you need in your cisco pix to forwards vpn packets for
your external card of your isa server is:

 

static (inside,outside) "External IP from PIX"  "External IP ISA netmask
255.255.255.255 

conduit permit gre host "External IP PIX" any

conduit permit tcp host  "External IP PIX" eq 1723 any

conduit permit udp host  "External IP PIX" eq 1723 any

 

ex: static (inside,outside) xx..xx.xx.xx yy.yy.yy.yy netmask
255.255.255.255 

conduit permit gre host xx..xx.xx.xx any

conduit permit tcp host xx..xx.xx.xx eq 1723 any

conduit permit udp host xx..xx.xx.xx eq 1723 any

 

you also can use access list for permit the traffic, is the same to use
conduits.

 

 

 

Federico Muller

MOS, MCSA, MCSE, MCT, CCNA, Security+

Training & Consulting Manager

TeKnowlogic Dominicana

Tel.: (809) 683-6646 Fax: (809) 683-6608

  _____  

From: Lian-Wee LOO [mailto:lwloo@xxxxxxx] 
Sent: Monday, April 05, 2004 11:02 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Cisco Pix 535

 

http://www.ISAserver.org

I am not sure, I don't think they will change. Anyway to resolve? What
are the port need to be open in order for me to connect to ISA VPN
server? It always stuck at the user authentication part, should be error
721. Please advice. Thank you...

 

best regards,

lwloo 2k'3

 

  _____  

From: Thomas W Shinder [mailto:tshinder@xxxxxxxxxxx] 
Sent: Monday, April 05, 2004 8:29 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Cisco Pix 535

 

http://www.ISAserver.org

Hi Lian,

 

Sounds like the PIX is misconfigured, which is a common problem.

 

They might want to consider upgrading the PIX to ISA 2004.

 

HTH,

Tom

 

  _____  

From: Lian-Wee LOO [mailto:lwloo@xxxxxxx] 
Sent: Monday, April 05, 2004 4:47 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] Cisco Pix 535
Importance: High

http://www.ISAserver.org

I am behind Cisco PIX 535 and tried to connect to my office VPN which is
on MS ISA. It always stuck at the verifying user/password (Error 721 if
I am not mistaken). Any idea? Please help...

 

best regards,

lwloo 2k'3

 

 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
tshinder@xxxxxxxxxxxxxxxxxx
To unsubscribe send a blank email to
$subst('Email.Unsub')
------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
lwloo@xxxxxxx
To unsubscribe send a blank email to
$subst('Email.Unsub') 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
fmuller@xxxxxxxxxx
To unsubscribe send a blank email to
$subst('Email.Unsub') 

Other related posts: