cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
532
Views
5
Helpful
5
Replies

tunnel protection works with transport mode only???

yuhuiyao
Level 1
Level 1

Anyone know why tunnel protection works with transport mode only??? If I change it to tunnel mode, it stops working immediately.

Thanks,

1 Accepted Solution

Accepted Solutions

That is because Tunnel mode creates a new IP header which gets modified when is NATed, when the remote peer receives this new header which is NATed the Security numbers do not match to what it had generated. Using trasport mode keeps the original header and only encapsulates the payload.

View solution in original post

5 Replies 5

Ivan Martinon
Level 7
Level 7

Tunnel protection works with both modes, however transport mode is used when NAT is present along the path, which might be your case.

Thanks for your reply. You are correct I have nat firewalls in the path. Do you know why I have to use transport mode in case of nat?

Thanks,

That is because Tunnel mode creates a new IP header which gets modified when is NATed, when the remote peer receives this new header which is NATed the Security numbers do not match to what it had generated. Using trasport mode keeps the original header and only encapsulates the payload.

tried transport mode with tunnel protection on gre interfaces, plus no crypto ipsec nat-transparency udp-encaps, not working with nat is present, any idea?

What is the actual error you get? do you complete the tunnel? are you not passing traffic? can you post your configs and debugs?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: