cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
478
Views
3
Helpful
2
Replies

General IPSEC question

rasoftware
Level 1
Level 1

I know Cisco used 4500 UDP to capsulate ESP over a NAT device.

Checkpoint seem to use 2746. But later verison use 4500 same as Cisco/Juniper. Can anyone confirm IEFT port is the industry standard? I guess 4500.

Strange question but something I need to know..

2 Replies 2

m.sir
Level 7
Level 7

Yes u are right port port UDP encapsulation is 4500 its ietf rfc you can check it here....

http://www.ietf.org/rfc/rfc3948.txt

I guess checkpoint R55/56 using 2746 and then changing to 4500 in the R60 release would indicate a move to the industry standard.

I only ask because I have a client using old checkpoint over a CBAC/NAT 1800 and have all kinds of trouble. This doesnt appear to be the case with the later client which works more like the cisco using 4500.