<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PPTP (Point-to-Point Tunneling Protocol) through PIX Firewall</title>
	<atom:link href="http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/</link>
	<description>Computer and technology tutorials and guides</description>
	<lastBuildDate>Sat, 21 Nov 2009 18:18:34 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: </title>
		<link>http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/comment-page-1/#comment-3228</link>
		<dc:creator></dc:creator>
		<pubDate>Thu, 11 Jan 2007 13:58:12 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-3228</guid>
		<description>There is a nice solution for Connecting a Cisco PIX to Windows Vista.
Configure L2TP without certificates to seamlessly migrate from PPTP to L2TP.
http://support.dmu.edu/VistaandCiscoPIXpptp/index.html</description>
		<content:encoded><![CDATA[<p>There is a nice solution for Connecting a Cisco PIX to Windows Vista.<br />
Configure L2TP without certificates to seamlessly migrate from PPTP to L2TP.<br />
<a href="http://support.dmu.edu/VistaandCiscoPIXpptp/index.html" rel="nofollow">http://support.dmu.edu/VistaandCiscoPIXpptp/index.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/comment-page-1/#comment-1517</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Mon, 28 Mar 2005 07:53:40 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-1517</guid>
		<description>&lt;ul id=&quot;quote&quot;&gt;&lt;h6&gt;Anonymous wrote:&lt;/h6&gt;Try adding &quot;fixup protocol pptp 1723&quot; instead of all of the changes above.&lt;/ul&gt;

This is right on, works like a champ. This only works in PIX version 6.3.3 and up.

The fixup now takes care of translating the GRE tunnel to a natted  internal ip.</description>
		<content:encoded><![CDATA[<ul id="quote">
<h6>Anonymous wrote:</h6>
<p>Try adding &#8220;fixup protocol pptp 1723&#8243; instead of all of the changes above.</ul>
<p>This is right on, works like a champ. This only works in PIX version 6.3.3 and up.</p>
<p>The fixup now takes care of translating the GRE tunnel to a natted  internal ip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ko</title>
		<link>http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/comment-page-1/#comment-1118</link>
		<dc:creator>ko</dc:creator>
		<pubDate>Tue, 07 Dec 2004 14:35:15 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-1118</guid>
		<description>you need to check your recipe! you should never open port 137,138,139 to any machine from the internet. 

PPTP uses TCP 1723 and GRE (protocol 47) 

ports 137-139 are opening HUGE HOLES in your network security. Especially if it is to a Microsoft server, esentialy you have told people to open their windows shares to the World. NEVER OPEN these ports.

 I don&#039;t coment on much but this is bad networking practices at their worst.</description>
		<content:encoded><![CDATA[<p>you need to check your recipe! you should never open port 137,138,139 to any machine from the internet. </p>
<p>PPTP uses TCP 1723 and GRE (protocol 47) </p>
<p>ports 137-139 are opening HUGE HOLES in your network security. Especially if it is to a Microsoft server, esentialy you have told people to open their windows shares to the World. NEVER OPEN these ports.</p>
<p> I don&#8217;t coment on much but this is bad networking practices at their worst.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/comment-page-1/#comment-1070</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Tue, 23 Nov 2004 14:21:07 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-1070</guid>
		<description>Try adding &quot;fixup protocol pptp 1723&quot; instead of all of the changes above.</description>
		<content:encoded><![CDATA[<p>Try adding &#8220;fixup protocol pptp 1723&#8243; instead of all of the changes above.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/comment-page-1/#comment-452</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 25 Aug 2004 01:15:38 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-452</guid>
		<description>I&#039;ve got a same problem... If I delete the static rule, all other computers have an Internet access otherwise not :?  :cry:</description>
		<content:encoded><![CDATA[<p>I&#8217;ve got a same problem&#8230; If I delete the static rule, all other computers have an Internet access otherwise not :?  :cry:</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fluffy</title>
		<link>http://www.tech-recipes.com/rx/382/pptp-point-to-point-tunneling-protocol-through-pix-firewall/comment-page-1/#comment-177</link>
		<dc:creator>Fluffy</dc:creator>
		<pubDate>Wed, 12 May 2004 08:15:16 +0000</pubDate>
		<guid isPermaLink="false">guid-fix-me!#comment-177</guid>
		<description>ok I&#039;m a newbie when it comes to setting up this pix.  When I add that static statement and the other access-list commands I can get into the network via vpn just fine, but all the computers on the inside network lose internet access.  I took out the access-list and still had the same problem so I&#039;m pretty sure it&#039;s caused by that static entry.  Can anyone tell me what I&#039;m doing wrong?</description>
		<content:encoded><![CDATA[<p>ok I&#8217;m a newbie when it comes to setting up this pix.  When I add that static statement and the other access-list commands I can get into the network via vpn just fine, but all the computers on the inside network lose internet access.  I took out the access-list and still had the same problem so I&#8217;m pretty sure it&#8217;s caused by that static entry.  Can anyone tell me what I&#8217;m doing wrong?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
