Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Cisco VPN 5000 Client behind NetScreen 25

I have difficulties connecting to Cisco VPN 5000 .I am using VPN 5000 Client

behind NetScreen 25 firewall with policy based NAT . I have opened UDP/500

IP/50 and ip/51 to pass trough on NetScreen device. If " NAT transparency mode" on VPN Client is enabled i can't establish connection with VPN concentrator . If "NAT transparency mode" is disabled i can establish VPN connection but can not access resources on remote site .

I would be grateful for any suggestion on that issue !

1 REPLY
New Member

Re: Cisco VPN 5000 Client behind NetScreen 25

Nat transparency mode for VPN 5000 default is using TCP port 80 (HTTP) to connect.

You need to open that port on the firewall as well.

If you get connection with the remote VPN 5000 but can not ping anything, that is normal. I belive the Netsreeen is doing natting for all the PCs behind it.

So you need to use "NAT transparency mode".

Another thing you can try is that you can change the TCP 80 to TCP 10000 or other for NAT transparency on the VPN 5000.

Best Regards,

Paul Qiu

169
Views
0
Helpful
1
Replies