Urgent - Win2K to Cisco PIX - VPN
Urgent - Win2K to Cisco PIX - VPN
Author
Discussion

TheExcession

Original Poster:

11,669 posts

280 months

Thursday 20th January 2005
quotequote all
Anyone done VPNs from a Win2K box into a Cisco PIX.

I need to get it setup pretty urgently for part of the WRC - there is a router behind a PIX firewall that I need to re-configure - at the moment we can't get any timing data from the stages back to the Service Park.

I can ssh into the PIX but it won't telnet from there (security reasons I spose).

So any pointers for the PIX config and what to do at the Win2k box.

Many thanks
Ex

P.S. can use an XP box if that makes it easier.

edit: PIX is version 6.3(3) - just down laoding the vpn client too

>>> Edited by TheExcession on Thursday 20th January 12:33

IPAddis

2,525 posts

314 months

Thursday 20th January 2005
quotequote all
I've tried it and didn't get it to work. However I'm not a firewall expert.

I do know there are articles on Microsoft and Cisco's web site giving a run through of exactly how to setup this scenario.

Ian A.

rich-uk

1,431 posts

286 months

Thursday 20th January 2005
quotequote all
You need to make sure the VPN tunnel is established, then you should be able to administer the router as if it was next to you.

Have you got the closed padlock icon in the bottom right of your screen, next to the time?

tallbloke

10,376 posts

313 months

Thursday 20th January 2005
quotequote all
As a temporary way round, you could port forward 3389 to the internal ip addy of the w2k server from the pix. Then just run a remote desktop session from the xp box to the real world addy of the pix. I assume you are running terminal services on the w2k box. For some security you might want to set the pix to only allow a connection through if it comes from the ip of the site your logging in from.

HTH

>> Edited by tallbloke on Thursday 20th January 15:09

malman

2,258 posts

289 months

Thursday 20th January 2005
quotequote all


I think he's saying that he needs the pix to be the endpoint as he wants to configure a cisco router behind the pix. He wants to use 2k or xp as the client machine.

Thats how I read it

Never had a go at a pix so can't really help sorry

TheExcession

Original Poster:

11,669 posts

280 months

Thursday 20th January 2005
quotequote all
malman said:


I think he's saying that he needs the pix to be the endpoint as he wants to configure a cisco router behind the pix. He wants to use 2k or xp as the client machine.

Thats how I read it

Never had a go at a pix so can't really help sorry


Thats was the plan - but I found a work around.

More later

best
Ex

tallbloke

10,376 posts

313 months

Thursday 20th January 2005
quotequote all
malman said:


I think he's saying that he needs the pix to be the endpoint as he wants to configure a cisco router behind the pix. He wants to use 2k or xp as the client machine.

Thats how I read it


Yep sorry, misinterpreted it. That'll teach me to read twice before shooting my mouth off.

BliarOut

72,863 posts

269 months

Thursday 20th January 2005
quotequote all
TheExcession said:

malman said:


I think he's saying that he needs the pix to be the endpoint as he wants to configure a cisco router behind the pix. He wants to use 2k or xp as the client machine.

Thats how I read it

Never had a go at a pix so can't really help sorry



Thats was the plan - but I found a work around.

More later

best
Ex

Did you enable PPTP passthru

TheExcession

Original Poster:

11,669 posts

280 months

Thursday 20th January 2005
quotequote all
BliarOut said:
Did you enable PPTP passthru

Not quite

Anyone interested in this? thought not but here goes anyway.

The problem the WRC always had was getting the times back from the stages back to the computer result systems at the Rally HQ - actually the results go to the Service Park first but that's by the by.

They used to use a UHF system - so all the Timing Cabinets out on stage had UHF radios in them and the results were relayed via an aeroplane back to the Service Park. It's expensive keeping a plane up for the duration of the rally - plus you need two of them as they will need to refuel andthe rally doesn't stop while the sort that out.

So, Inmarsat and the WRC got together to deploy satellite communication systems through out their network using ISDN and MPDS (Inmarsat's proprietry Mobile Packet Data System).

Good stuff - we setup a 'hub' in London (I say we - it was my idea) so that all the Timing Cabinets, Service Park and HQ systems could all connect together and share information.

In the olden days they'd have terrible problems linking the SP and HQ as they relied on local telecoms. Go some where like Kenya and there aren't any!

So everyone is happy, the WRC boys have got their network in a box - take it anywhere in the world, unpack it switch it on and away you go. No provisioning of local telecoms every time you land in a strange country and no reconfiguring of routers to dial different numbers.

Then we got a bit more clever - the top WRC cars carry a GPS logger to provide data for Virtual Spectator animations. There was room for improvement here as often with the afternnon stages the cars wouldn't be back in Service Park in time for any of this data to make it into the TV program.

So we deployed wireless LAN at the timing controls and sucked the data off the cars out in the field. Then used an ISDN call to move the data back to SP. ISDN over satellite is expensive so once all the data was sent and the remaining ordinary cars were coming through the Time Controls would switch over to MPDS.
This service is charged by the bit and not by the minute and the timing data is very small - ideal solution.

So as you can see the Hub in London had to terminate ISDN and MPDS calls (these are PPP coming in through L2TP).

What happened recently was the hub equipment was moved out of a managed ISP and in house. Unfortunately they hadn't provisioned an ISDN PRI line so they had to goof with BRI lines. This required a change in hardware on the hub router and then a change in IOS.

Next thing we knew ISDN calls weren't connecting properly - never completing IPCP, bitching about I don't know what - I couldn't log in to see!

So, we dropped an old 1600 series router into the hub network and then managed to talk someone through setting it up so that the Service Park router would connect via ISDN over satellite.

We managed to get a ADSL line installed into the Service Park and then I could do this:

Telnet to Service Park via my satellite link through their ADSL line then,
Telnet into the Hub 1600 router from SP via ISDN over inmarsat satellite.
& finally telnet into the Hub Router

I still can't figure out why IPCP doesn't converge - but that's for another day - their systems are linked in via the 1600.

So, I'm off down the pub happy in the knowledge that for the first round of the WRC in 2005 the timing data will be safely winging its way all round the world thanks to itsy bitsy little old me.

best
Ex




tallbloke

10,376 posts

313 months

Thursday 20th January 2005
quotequote all
Cor!

What couldn't you do via ssh that you can via telnet?

malman

2,258 posts

289 months

Friday 21st January 2005
quotequote all
Aahhh! The simplest solutions are always the best