cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
505
Views
5
Helpful
3
Replies

isakmp nat-traversal

ronshuster
Level 1
Level 1

We have a number of lan to lan vpns and all works well as well as remote access vpn.

however there are a number of people who cannot access remote access vpn and when i add : isakmp nat-traversal 10 it works.

Any idea?

Also, when configuring site to site vpn using the wizzard (asdm) it removes the nat-travesal.

Any idea?

3 Replies 3

andrew.prince
Level 10
Level 10

NAT-T allows the negotiation of the VPN to be further encapsulated in UDP using port 4500.

This should be used when the remote end devices are performing NAT and do not understand or perform IPSEC pass-thru.

NAT-T is a global IKE setting.

HTH>

I understand thank you.

I guess it cannot hurt to have it turned on all the time.

Thank you again Andrew!

np - glad to help.