12-16-2009 07:11 AM - edited 02-21-2020 04:25 PM
Hi,
I can make a remote access vpn with ASA using its outside IP, every thing goes well. As soon as I add static NAT on the router for ASA's outside IP & try vpn with the global IP following error comes on the ASA whereas I can see the translation on the router(udp-500-inside global is traslated to udp-500-inside-local IP)
PC------Router--------ASA
NAT-T is enabled on the ASA.
Can anyone share their experiences when ASA is behind a NAT box & how ASA can recognize its identity inside IPSEC packets sent by the client.....
Regards,
Ak
12-17-2009 02:12 AM
Is the router configured for firewalling?
12-17-2009 03:24 AM
Hi Andrew,
On behalf of my colleague I would like to inform you that Router is not configured for firewalling. IPSec traffic is directly coming to internet router and being forwarded to ASA.
Regards,
12-17-2009 04:03 AM
OK - for NAT-T to work effectivley, both ends need to negotiate it and support it, does the remote end of the VPN have NAT-T settigns?
12-17-2009 04:18 AM
On the other end , we are using Cisco VPN client and NAT-T is also configured there i.e IPSec over UDP ( NAT/PAT ) option.
Thanks
12-17-2009 04:20 AM
Ahh yes - sorry I missed that in the original post, can I ask you to post the output from the VPN client log? Also the router debug output - removing any sensitive information of course.
12-17-2009 10:40 AM
According to the picture you have several retransmisions. When you use NAT-T the ASA will switch from using UDP 500 to UDP 4500 for the negotiation and to pass traffic. Make sure that UDP 4500 is not getting blocked.
Cheers!
- Yamil
12-19-2009 01:40 PM
every thing is allowed both on the firewall & the router. I think there is some identity issue bc router is changing dst ip in the IP header & the IPSEC header is having a public IP not belonging to ASA.....lets see if some one faces similar issues. I am planning to assign public IPs directly on the firewall to avoid problem caused by NAT......
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: