Cisco Systems, Inc.(R)    Cisco | Profile | Contacts & Feedback | Help
Cisco SMB Support Assistant
Modify Security for an Internal VPN Server
Home > Work With My Routers > Cisco Routers > Modify Security for an Internal VPN Server  
 

Modify Security for an Internal VPN Server




Introduction

This document explains how to modify your router security settings so that you can use an internal VPN server.


Back to Top



Requirements


Back to Top



Modify Security for a VPN Server

If you have a Microsoft PPTP VPN server inside your network, you can modify the security settings to allow VPN traffic. To modify your firewall to allow Microsoft PPTP VPN traffic, follow these steps:

Note: You do not need to make any changes to allow internal users to access a VPN outside your network.

Add an ACL Rule for VPN Traffic

To create a firewall rule to allow Microsoft PPTP VPN traffic, follow these steps:

  1. Open a web browser and type http://router-IP-address in the Address field. The router's IP address is the IP address that you entered in the LAN Addressing Worksheet (field L6A).

    Note: For further information about how to launch SDM, refer to Configure Your Router with Security Device Manager.

  2. Click Configure.

    intvpn-sdm_conf.gif

  3. Click the Firewall and ACL tab.

    intvpn-1.gif

  4. Click Edit Firewall Policy/ACL.

  5. In the From interface, select your WAN interface and in the To interface select your LAN interface. Click Go.

    intvpn-firewall3b.gif

  6. Choose Returning Traffic.

  7. Follow these steps to allow PPTP VPN traffic on TCP port 1723:

    1. Next to Services, click Add > Insert After.

      intvpn-firewall4b.gif

    2. Next to Select an action, choose Permit.

      intvpn-firewall5b.gif

    3. Under Source Host/Network, choose Any IP Address.

      intvpn-firewall6b.gif

    4. Under Destination Host/Network, choose Any IP Address.

      intvpn-firewall12b.gif

    5. Under Protocol and Service, choose TCP.

      intvpn-firewall13b.gif

    6. Under Destination Port, replace the word any with 1723. Click OK to select the service, then click OK to confirm the rule.

      intvpn-firewall15b.gif

  8. Follow these steps to allow PPTP VPN traffic on IP port 47:

    1. Next to Services, click Add > Insert After.

    2. Next to Select an action, choose Permit.

    3. Under Source Host/Network, choose Any IP Address.

    4. Under Destination Host/Network, choose Any IP Address.

    5. Under Protocol and Service, choose IP.

    6. Under IP Protocol, click the details button (...) and select gre (47). Click OK to select the service, then click OK to confirm the rule.

Create an Address Translation Rule for VPN Traffic

To create an address translation rule to allow Microsoft PPTP VPN traffic, follow these steps:

  1. Follow these steps to add an address translation rule for TCP port 1723:

    1. Click the NAT tab.

      intvpn-firewallnat8a.gif

    2. Click Add to add a new translation rule.

      intvpn-firewallnat3b.gif

    3. At the Add Address Translation Rule screen, choose Static. Next to Direction, choose From inside to outside.

      intvpn-firewallnat4stata.gif

    4. Under Inside Interface(s), enter the internal IP address of your server that you entered in field F5 of the Internet Services worksheet.

      intvpn-firewallpat1.gif

    5. Under Outside Interface(s), enter the public IP address of your WAN connection.

      intvpn-firewallpat2.gif

    6. Under IP Address, check Redirect Port. Choose TCP and enter port 1723 in the Original Port and Translated Port fields.

      intvpn-firewallpat4a.gif

    7. Click OK to confirm.

  2. Click File > Write to Startup Config to save your configuration.


Back to Top



Next Step

You have now modified your router security settings for an internal VPN server.

To make further changes to your router, refer to the Router Support Page.

To set up other devices on your network, refer to the Configuration Overview page.


Back to Top



Troubleshoot the Procedure

Problem

Cause(s) and Suggested Solution(s)

I added a new firewall rule and I cannot access the router.

Contact the SMB Technical Assistance Center (SMB TAC) for assistance.


Back to Top



Related Information

Service Requests

  Open a service request
  Update a service request

Feedback

Please rate this document.
++ + +/- - --

This document solved my problem.

Yes No Just Browsing

Suggestions for improvement:




If Cisco may contact you for more details
or for future feedback opportunities,
please enter your contact information.

Full Name:
E-mail:



© 1992-2006 Cisco Systems, Inc. All rights reserved. Terms and Conditions, Privacy Statement, Cookie Policy and Trademarks of Cisco Systems, Inc.