Errors of PIX OS 7.0 with outgoing PPTP traffic, inspect inspection do not?

Since the upgrade to 7.0, a PIX515 continues to spew the following errors when inside client PPTP traffic passes through the PIX for an external PPTP server (another PIX running 6.3, VPN3030, etc.):

% 3 PIX-305006: failure of the regular creation of translation for the Protocol 47 src inside:10.x.y.z dst outside:216.x.y.z

% 3 PIX-710003: GRE denied by the ACL on 216.x.y.z/0 outside:70.x.y.z/0

Mistakes repeat tirelessly during the session of the PPTP client if the session will come and pass traffic.

I'm running 7.01.5 now, and all previous versions of 6.x worked well, without errors, using the command "fixup protocol pptp 1723". In the current configuration, I have a pptp "inspect" in my world map policy. This PIX uses PAT on his address to the outside.

Any ideas?

You're probably hitting http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=CSCei27070&Submit=Search, already fixed in 8 7.0 (1), which was not actually built and tested again a regression.

Keep checking http://www.cisco.com/cgi-bin/tablebuild.pl/pix-interim for when it came out. The question seems essentially cosmetic, even if it does not indicate that the connections will be de-energized after awhile, but more detailed descriptions on this bug say that this situation of abandonment is quite rare.

Tags: Cisco Security

Similar Questions

Maybe you are looking for