Point-to-Point Tunneling Protocol (PPTP)
An early VPN protocol that tunnels PPP sessions across an IP network; its usual authentication and encryption pairing has known weaknesses, so it is treated as obsolete.
Point-to-Point Tunneling Protocol, published as RFC 2637 in 1999, was one of the first widely deployed remote access VPN protocols. It carries PPP frames across an IP network: a TCP control connection manages the tunnel, and the PPP traffic itself is wrapped in a modified form of Generic Routing Encapsulation (GRE). PPTP defines no encryption of its own. Confidentiality came from Microsoft Point-to-Point Encryption (MPPE), with users usually authenticated by MS-CHAPv2, a variant of CHAP.
That pairing is the reason PPTP is now considered insecure. MS-CHAPv2 has published weaknesses that allow a captured authentication exchange to be cracked, and MPPE derives its keys from that exchange, so recovering the credentials can expose the session. Because GRE is its own IP protocol rather than TCP or UDP, PPTP also had trouble crossing some firewalls and NAT devices. Its replacements are L2TP combined with IPsec, IPsec on its own with IKE, and VPNs built on TLS. L2TP is often described as PPTP’s successor, but L2TP itself provides no encryption either, which is why it is paired with IPsec.
Exam relevance: a scenario that asks for a secure remote access protocol is likely to present PPTP as a distractor. Candidates are expected to recognise PPTP as legacy and to prefer IPsec or TLS-based VPNs.