How to allow access to the external network of VPN through PPTP

Hi guys, this is probably a simple one, but I have not much firewall experience so any help is appreciated.

We would like to have the opportunity to connect to a private network virtual to a company, we have recently acquired.  When you connect to it directly from the Internet (not), it is accessible.  However, behind our firewall, there is no access.  We use Cisco ASA 8.2 (2)

Currently, we have an entry as follows:

PPTP tcp service object-group

EQ pptp Port object

inside_access_in list extended access permit tcp any host object_name object-group PPTP

Please can anyone advise what else are required to complete what I'm not sure of what else is needed?  Basically, we want any device within our network in order to access the VPN through PPTP.

Your help is appreciated

Kind regards

Hi Angelo,.

It should work when you make a pptp permitted and inspected. But will also Appreciate ACL with your firewall to the PPTP server.

http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a0080094a5a.shtml#pptpwith

The above documents helps you better understand.

Please assess whether the information provided is useful.

By

Knockaert

Tags: Cisco Security

Similar Questions

  • Access to the external network when connected to the VPN

    I have a 5505 I successfully install an IPSEC connection to. It uses NT to Active Directory authentication to authenticate. After I log in, I can access everything on the remote network (internal). I can't access anything on the internet.

    Nothing behind the ASA can access internet, vpn clients that cannot come back on.

    Syslog messages show buiding vpn clients to the top and down the ICMP connections if they try to do a ping to the outside, but they are not answered.

    I know it's most likely a statement ACL or NAT that I am out of ideas?

    config attacched

    You have 2 options.

    Split tunneling, unencrypted access to internet.

    Public Internet on a stick, integrated internet traffic to ASA and back on.

    permit same-security-traffic intra-interface

    Global 1 interface (outside)

    NAT (outside) 1

  • HP Officejet 6500 a Plus: how to allow access to the ePrint and still block direct wireless printing?

    My web access is on a public network that I can't control.  I feel ePrint installation and it works fine, but I have a number of people who directly print on my printer and wish to block this direct printing for the ePrint which I can control through allowed/blocked senders lists.

    Firstly, is it still possible?

    It it is possible, how do I do to fix this?

    Thank you

    Hi @Unhappy_Camper ,

    Welcome to the HP forum.

    I understand that you want to prevent other people from printing on your 6500 has more.

    Unfortunately what you would do, is not possible.

    Anyone on the network can see and use the printer.

  • How to allow access to a local area network behind the cisco vpn client

    Hi, my question is about how to allow access to a local area network behind the cisco vpn client

    With the help of:

    • Cisco 5500 Series Adaptive Security Appliance (ASA) that is running version 8.2 software
    • Cisco VPN Client version 5.0 software

    Cisco VPN client allows to inject a local routes in the routing table Cisco ASA?

    Thank you.

    Hi Vladimir,.

    Unfortunately this is not a supported feature if you connect through the VPN Client. With VPN Client, that the VPN Client can access the VPN Client LAN host/local machine, not host from the local network to business as customer VPN is not designed for access from the local company network, but to the local corporate network.

    If you want to access from your local business to your LAN network, you need to configure LAN-to-LAN tunnel.

  • How to allow access to all users of the connection on my computer?

    How to allow access to all users of the connection on my computer?

    Your question is hard to understand.  I interpret as:

    "How to allow all the users on my computer to access some files or folders?

    The answer depends somewhat on the question of whether you have XP Pro or XP Home, but a general answer is found the following article.

    "How to use file sharing Simple to share files in Windows XP"
      <>http://support.Microsoft.com/kb/304040 >

    Click on "level 3: files in shared documents available to local users"

    HTH,
    JW

  • How to restrict access to the network for customers in the lobby.

    Hello

    How is - this preferable to limit the access of the data ports in the lobby of the company for Internet access only? Although the hosts are not on the field, is it safe to allow them to reach the port of data?

    I suggest setting up a vlan separate for these ports and usig dot1q on trunk this vlan to a DMZ interface dedicated or the subinterface on your firewall with an ACL that only allows access to the internet. That should do the trick.

  • access to the default in IIS6 and IIS7 Web site, how we configure IIS6 on windows 7 to allow access to the default Web site

    How to configure IIS6 on windows 7 to allow access to the default Web site or there at - there someone out there who can put up my computer at a reasonable rate of legend

    Hello

    The question you posted would be better suited in the TechNet Forums. I would recommend posting your query in the TechNet Forums.

    http://social.technet.Microsoft.com/forums/en-us/winserverfiles/threads

  • Is it posible to allow access between the host and virtal machine without wired network?

    I want to use my laptop to show him that I did in the virtual work to other people at my home.

    However, the laptop is ofen not allowed access to the network in their office.

    Is it posible to allow access between the host and virtal machine without wired network?

    VMware player

    My virtual machine is filled to the physical network adapter and use the static IP address.

    Brad

    Setting of the virtual machine: filled

    Change that to each host only (what Continuum called VMnet1) or NAT (VMnet8).  Both use a separate virtual NETWORK card to connect the physical computer virtual host, independent of any NETWORK adapter on the host.

    ... Since the machine host (win7) could not get IP, ping fail to VM (192.168.1.5)...

    Because the connection between the guest and the host is through a separate NETWORK card, you must use the 'other' IP address.  Access a prompt on the host computer and type IPCONFIG to view the IP address of VMnet1 and VMnet8 NIC.  Then use this IP address instead of 192.168.1.5.

    And when you have changed the network management modes (i.e. of bridged to host-only), Windows does not automatically renew its IP address.  The virtual NETWORK card uses a different subnet if you need to renew your DHCP lease or change your static IP address to work with the new subnet.

  • Photo Gallery can't open the photo because you are not allowed access to the location of the file

    Photo Gallery can't open the photo because you are not allowed access to the location of the file some of the image are open

    Click on the folder and change your permissions for it and all subfolders and files all rights and if necessary take hand the case (and maybe the parent folder or even its parent - and all of the subfolders and files) until you have the permission you need.  Here are the general procedures to help you:

    To view your permissions, right-click on the file/folder, click Properties, and check the Security tab.  Check the permissions you have by clicking on your user name (or group of users).  Here are the types of permissions, you may have: http://windows.microsoft.com/en-US/windows-vista/What-are-permissions.  You must be an administrator or owner to change the permissions (and sometimes, being an administrator or even an owner is not sufficient - there are ways to block access (even if a smart administrator knows these ways and can move them - but usually should not because they did not have access, usually for a very good reason).)  Here's how to change the permissions of folder under Vista: http://www.online-tech-tips.com/windows-vista/set-file-folder-permissions-vista/.  To add take and the issuance of right of permissions and ownership in the right click menu (which will make it faster to get once it is configured), see the following article: http://www.mydigitallife.info/2009/05/21/take-and-grant-full-control-permissions-and-ownership-in-windows-7-or-vista-right-click-menu/.

    To resolve this problem with folders, appropriating the files or the drive (as an administrator) and give you all the rights.  Right-click on the folder/drive, click Properties, click the Security tab and click on advanced and then click the owner tab.  Click on edit, and then click the name of the person you want to give to the property (you may need to add if it is not there--or maybe yourself). If you want that it applies to subfolders and files in this folder/drive, then check the box to replace the owner of subcontainers and objects, and click OK.  Back and now there is a new owner for files and folders/player who can change the required permissions.  Here is more information on the ownership of a file or a folder: http://www.vistax64.com/tutorials/67717-take-ownership-file.html.  To add take ownership in the menu of the right click (which will make it faster to get once it is configured), see the following article: http://www.howtogeek.com/howto/windows-vista/add-take-ownership-to-explorer-right-click-menu-in-vista/.

    Good luck and I hope this helps!

    Lorien - MCSA/MCSE/network + / has + - if this post solves your problem, please click the 'Mark as answer' or 'Useful' button at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • Failed to create the external network

    Hi all.

    Well, I have deployed VIO with NSX. I created 2 virtual machines (instances) with 2 internal networks. I created router, plugged on both networks. Tried to ping of vm1 (int_net1) to the virtual machine 2 (int_net2) through router - everything works fine.

    So, the next step was to provide access to Internet of the virtual machines. I try to create the shape of external network Admin-> Control Panel-> network-> network create system:

    Name: extnet1

    Project: MyProject

    Type of network provider: dish (deployment master I chose NSX environment and VLANs separated to outside networks)

    Admin State: checked

    External network: checked

    When I press the button "Create network" an error has occurred: ""Error: failed to create the extnet1 network '. " How can I create external network?

    Thank you all for help. I solved my problem. For the future: you can only use "PortGroup" in Type of network provider. So when I chose PortGroup and set it to the external network 'dvportgroup-XX' have been created.

    controller01 2015-08-12 07:51:34.847 INFO [req-e17f7e0a-fd22-4f06-ba05-76c760b7d6f8 neutron.api.v2.resource None 11320] create failed (client error): Invalid input for operation: GRPE caught ports support only on external networks.

  • Supply Machines on the external network of non-domaine Thinapps joined: invalid HTTP 404 status Code

    So, I want to put at the disposal of the thinapps of non-domaine joined Machines on the external network through the workspace. Is this possible?

    When I access the URL in such a condition, in the HorizonThinAppClient.log, I get the following:

    2015-02-23 08:48:43 [INFO] [9860.9344] [hzntaclnt::InstallDb:DownloadFileToCache] download https://workspace.domain.com/SaaS/API/1.0/rest/user/applications/download/edf74562-6c32-4BE9-8C3A-74f792de4d1e/Tm90ZXBhZCsrLmV4ZQ== at C:\Users\Joe\AppData\Local\VMware\Horizon ThinApp\PackageCache\Notepad++\HTA715B.tmp

    2015-02-23 08:48:43 [ERROR] [9860.9344] [hzntaclnt::HttpConnection:DownloadToFile] the code invalid HTTP status 404 (not found)

    2015-02-23 08:48:43 [ERROR] [9860.9344] [hzntaclnt::InstallDb:DownloadFileToCache] download failed, error SC_HTTP_RESPONSE_CODE (unexpected HTTP response code: not found)

    2015-02-23 08:48:43 [ERROR] [9860.9344] [hzntaclnt::InstallDb:DoInstallFile] download failed for "Notepad ++" (\\fileshare.domain.local\ThinappsHorizon\Notepad++\Notepad++.exe), SC_HTTP_RESPONSE_CODE (unexpected HTTP response code: not found)

    2015-02-23 08:48:43 [ERROR] [9860.9344] [hzntaclnt::InstallDb:Install] failed to install the package from the file ' Notepad ++ ' (\\fileshare.domain.local\ThinappsHorizon\Notepad++\Notepad++.exe): SC_HTTP_RESPONSE_CODE (unexpected HTTP response code: not found)

    What I have to be on the local network to download the Thinapp packages, or am I misconfigured? I already checked the user who runs has full rights to share inside and on the local network, it works fine, but when mandated by workspace it fails, probably because the client calls a share location, that it cannot reach. Anyone who encountered this?

    You use the option "Enable account based on access '? Please see VMware Workspace Portal 2.1 Document Center for documentation on how make thinapps available to computers not joined to a domain.

  • regarding the connection of the virtual machine to the external network

    Hi all

    I'm new to vmware and I have two virtual machines with windows operating system 7. How to connect to the external network?
    can I assign a NATed IP to them?

    If the need to talk about virtual computer internally, you can add all the VM in the same VSS(vswitch 1) at the same port group Network2 VLAN40. for virtual machines on that VLAN can communicate among themselves without problem and configure all virtual machines with IPs in VLAN40. no need for an another vs.

    For internet access, first check with your network administrator, if the VLAN has a routing or this VLAN has access to the DNS server that provide internet or the proxy server for internet access. He will confirm. or you can also check if this virtual machine are able to ping your DNS server or proxy servers. If its power of ping so it has access to this network. Configure the virtual machines that you configure a physical computer for internet access.

    If the VLAN has access to the internet, even that you configure the physical server with connection DNS and proxy for internet access only the configuraiton even here too in the virtual machine.

  • Qosmio F30 - how to get started using the external CD/DVD drive?

    Hello Mr President

    I have a Qosmio F30. My CD/DVD drive does not work. I have the USB CD/DVD drive, but I think that F30 does not support external USB CD/DVD drive to boot to the top.

    Please help me. Now, how can I boot Windows XP CD?

    At first, I must say that I really wonder why you do not have something to trade integrated optical drive. Qosmio F30 is not that old laptop and is perhaps the warranty still valid. You should check with the partner of service authorized in your country.

    For start with external peripheral is not so easy because the external drive doesn't recognize started upward. Theoretically you should either external ODD visible to your Qosmio. For older laptop, it is possible if you start Notepad in pilot mode and load BACK to BACK. After doing this you have access to the external hard drive and can start the installation.

    You can do this with your Qosmio laptop?

  • How can I access my Iomega external hard drive? When I plug it in it shows under COMPUTER.

    How can I access my Iomega external hard drive?  When I plug it into my USB port it shows on your DESKTOP.  I try to back up files on my external hard drive, but I can't get even the external hard drive on my computer.  Thanks for help.

    Hi Larryxcvb,

    1. what happens when you try to access the driver? You receive messages or error codes?

    2. other USB devices (USB key, etc.) recognized and works very well without any problem?

    3 is not detected the external hard disk on other computers?

    You can check the following link and try to run the Fixit of material.

    Hardware devices not detected or does not

    You can also visit the following iomega support article and see if it helps.

    What should I do if my Iomega USB hard drive is not assigned a drive letter or is not detected in Windows 7, Vista or XP?

    Hope this information is useful.

  • Cisco ASA 5505 remote VPN access to the local network

    I have installed two ASA 5505 VPN site to site that works perfectly.  Now, I also need to have 1 customer site to remote access VPN with Cisco VPN dialer.  I can get the VPN dialer to connect the VPN and get a VPN IP address, but I do not have access to the remote network.  can someone take a look and see what I'm missing?  I have attached the ASA running config.

    Apologize for the misunderstanding.

    To access the remote vpn client 10.10.100.x subnet, the vpn-filter ACL is the opposite.

    Please please share the following ACL:

    FROM: / * Style Definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-qformat:yes ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 cm 5.4pt cm 0 5.4pt ; mso-para-marge-haut : 0 cm ; mso-para-marge-droit : 0 cm ; mso-para-marge-bas : 10.0pt ; mso-para-marge-gauche : 0 cm ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;}

    outside_cryptomapVPN list of allowed ip extended access any 10.10.20.0 255.255.255.224

    TO:

    / * Style definitions * / table. MsoNormalTable {mso-style-name : « Table Normal » ; mso-tstyle-rowband-taille : 0 ; mso-tstyle-colband-taille : 0 ; mso-style-noshow:yes ; mso-style-priorité : 99 ; mso-style-qformat:yes ; mso-style-parent : » « ;" mso-rembourrage-alt : 0 cm 5.4pt cm 0 5.4pt ; mso-para-marge-haut : 0 cm ; mso-para-marge-droit : 0 cm ; mso-para-marge-bas : 10.0pt ; mso-para-marge-gauche : 0 cm ; ligne-hauteur : 115 % ; mso-pagination : widow-orphelin ; police-taille : 11.0pt ; famille de police : « Calibri », « sans-serif » ; mso-ascii-font-family : Calibri ; mso-ascii-theme-font : minor-latin ; mso-hansi-font-family : Calibri ; mso-hansi-theme-font : minor-latin ; mso-bidi-font-family : « Times New Roman » ; mso-bidi-theme-font : minor-bidi ;}

    outside_cryptomapVPN to access extended list ip 10.10.20.0 allow 255.255.255.224 all

    Hope that helps.

Maybe you are looking for

  • Email sending limit in MAIL

    I have the opportunity to send a simple email to up to 1,000 recipients, but whenever I do it, after 2 or 300, MAIL informs me that my outgoing server is unable to send the e-mail message. Then after an hour several wait, or a whole night, it works f

  • The print carriage moves do not

    The print on my Officejet 6500 Wireless carriage does not move to the Center, so I can replace the print cartridges.

  • How to scan to folder on IR1025n?

    I have IR1025n connected to the PC by USB cable.  printing works, but cannot scan.  any suggestions?  Thank you.

  • BlackBerry Smartphones Internet Explorer 6

    Is it possible to upgrade my blackberry curve to IE 6. I tried but can't.  Is there a software program I have to buy for this?  I appreciate all the information.  The site I am trying to get told that I must have internet explorer 6 and the browser t

  • Setup could not initialize - not the same issue as everyone else... ?

    HelloI'm pulling out my hair. When I run the exe to install for 2015 of CC, it IMMEDIATELY gives me a "Setup cannot initialize error:This is a new PC, built later than yesterday, m and there is no other teenagersoftware be installed on it. I've seen