Great Circle Associates Firewalls
(November 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: PPTP setup
From: rbc @ lava . net (Robert B. Carleton)
Date: Thu, 31 Oct 96 21:49 WET
To: Russ . Cooper . RC . on . ca @ GreatCircle . COM
Cc: firewalls @ GreatCircle . COM, drjarmon @ ingr . com
In-reply-to: <2191B2309F33D0118F7000A02458D19C000000005C9A @ NS> (message from Russ on Fri, 1 Nov 1996 01:12:13 -0500)

   From: Russ <Russ .
 Cooper .
 RC .
 on .
 ca @
 GreatCircle .
 COM>
   Date: Fri, 1 Nov 1996 01:12:13 -0500
   MIME-Version: 1.0
   X-Mailer: Internet Mail Connector (Beta) (4.5.1280.0)
   Content-Type: text/plain
   Content-Transfer-Encoding: quoted-printable
   Sender: firewalls-owner @
 GreatCircle .
 COM
   Precedence: bulk

   Don Jarmon asked...
   >I was planning to add a Dual NIC NTS4.0 server to a DMZ.  One
   >NIC configured to support PPTP and the other NIC connected
   >to the Intranet.  I was wondering 'bout what type of access is
   >needed on the boundry router to support Remote PPTP enabled
   >Internet Clients.

According to the internet draft the PNS, (PPTP Network Server)
receives an incoming TCP call on port 5678.  If that is true then the
DMZ external router would need to allow an incoming TCP call on port
5678 of the pptp server.

In a cisco, that would look something like this:

! pptp incoming to PNS
access-list 100 permit tcp 0.0.0.0 255.255.255.255 XXX.XXX.XXX.XXX 0.0.0.0 eq 5678

(where XXX.XXX.XXX.XXX is the PNS server IP address)

This access list could be refered to in the external interface setup
with a "ip access-group 100 in".  You might need to have additional
filter entries if you filter outbound packets from your DMZ router's
internal interface.

I haven't tried this but it seems reasonable,

			--Bruce

-- 
Robert B. Carleton + rbc @
 lava .
 net + http://www.lava.net/~rbc

Indexed By Date Previous:
From: (nil)
Next: Re: Firewalls-Digest V5 #598
From: "Stephen McLean - (0171 762 5177)" <steve . mclean @ sgst . co . uk>
Indexed By Thread Previous:
From: (nil)
Next: RE: PPTP setup
From: Russ <Russ.Cooper.RC.on.ca>

Google
 
Search Internet Search www.greatcircle.com