Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > GRE, hide nat on PIX

Reply
Thread Tools

GRE, hide nat on PIX

 
 
Jean-Michel Dewaal
Guest
Posts: n/a
 
      08-14-2005
Hi, Good Day,

Behind a PIX 501, I have a LAN hide nated to the external Interface of
the PIX. This works ok for tcp/ip traffic like http, ftp etc.

Behind, I have a host 10.10.10.10 that needs to get to an external
Internet located provided using PPTP.

It does not work. Sniffing, I see tcp ports being used. The client gets
to the point he has the login/password windows box to fill. Once done,
sniffing, I see ip-proto-47 (aka, GRE).

What to add to the PIX for the client being hide-nated to use a PPTP
server (not managed by us at all)???

I do not have anyhting like spare IP to static nat the client to an
internet IP.

PIX version : 6.3.4

Thanks,

Jean-Michel
 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      08-14-2005
In article <ddnhfr$6l3$(E-Mail Removed)>,
Jean-Michel Dewaal <(E-Mail Removed)> wrote:
:Behind a PIX 501, I have a LAN hide nated to the external Interface of
:the PIX. This works ok for tcp/ip traffic like http, ftp etc.

:Behind, I have a host 10.10.10.10 that needs to get to an external
:Internet located provided using PPTP.

:What to add to the PIX for the client being hide-nated to use a PPTP
:server (not managed by us at all)???

fixup protocol pptp 1723

http://www.cisco.com/univercd/cc/td/....htm#wp1067379

The PPTP fixup must be enabled for PPTP traffic to be translated
by PAT. Additionally, PAT is only performed for a modified
version of GRE (RFC2637) and only if it is negotiated over the
PPTP TCP control channel. PAT is not performed for the unmodified
version of GRE (RFC 1701 and RFC 1702).
--
Any sufficiently advanced bug is indistinguishable from a feature.
-- Rich Kulawiec
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
PIX 6.3.4 - Hide NAT before VPN Amaury Ronflard Cisco 2 08-14-2005 07:41 PM
PIX - mixing "nat 0 access-list" with nat/global pools Matthew Melbourne Cisco 2 02-12-2005 03:17 PM
tftp to srvr behind pix: use nat or no-nat? Jose Cisco 3 10-24-2004 02:42 PM
PIX Policy NAT: order of NAT commands Oleg Tipisov Cisco 4 08-13-2004 07:13 PM
Pix-to-Pix VPN - BOTH BOXES BEHIND NAT!!! Michael Gorsuch Cisco 1 10-24-2003 09:35 AM



Advertisments