cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4460
Views
10
Helpful
5
Replies

Site to site VPN port 4500

vpersaud001
Level 3
Level 3

Hello,

I have a site to site vpn between two Cisco 2811 routers passing through a PIX 515 on the core side and an ASA5510 on the remote side.

Although I have ports ESP and ISAKMP open the tunnel also requires udp port 4500.

Is that normal? If not any ideas how it can be fixed? Thanks.

1 Accepted Solution

Accepted Solutions

cisco24x7
Level 6
Level 6

On the Cisco 2811, do this:

no crypto ipsec nat udp

That will force the VPN tunnel to use ESP

instead of udp/4500

Easy right?

View solution in original post

5 Replies 5

cisco24x7
Level 6
Level 6

On the Cisco 2811, do this:

no crypto ipsec nat udp

That will force the VPN tunnel to use ESP

instead of udp/4500

Easy right?

Painfully easy. :) I'll use it after hours and post an update.

I guess the full syntax is "no crypto ipsec nat-transparency udp-encapsulation."

Thanks very much.

Issue resolved. Thanks again.

what if i need the opposite. i have some tunnels up on 4500 but one on port 500 down unidirectional. i know it would work on port 4500 but dont know how to push it to use it. any ideas?

@tommar if a VPN is established on udp/4500 then a VPN peer is behind NAT. If you have a tunnel established using udp/500, then neither peer is behind NAT.

 

If you've a problem with one tunnel, then ESP could be blocked - or you've got mismatched phase 1/2 settings.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card