MultiCash banking program and Cisco routers

After cleaning up traffic filtering rules on a Cisco 2851 router it turned out that the MultiCash banking program stopped working on hosts in the internal network.

The specific version of that program that I came across was using the PPTP protocol and GRE tunnels for establishing secure connections. Therefore I had to:

  1. Add an entry permitting GRE traffic to the ACL applied to the router’s WAN interface:
    permit gre any host A.B.C.D
    
  2. Add the PPTP protocol to the list of protocols inspected by SPI in the out direction on the router’s WAN interface:
    ip inspect name to-internet-ins pptp
    
Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s