cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
433
Views
0
Helpful
3
Replies

ipsec and nat

JOHN APONTE
Level 1
Level 1

i am trying to get ipsec protocol 50/51 to work on a 2811 router that is doing nat. i have created an acl to allow esp/ah on the in/out int but still not working. is there anything else required to allow ipsec to work with nat.

3 Replies 3

johnd2310
Level 8
Level 8

Hi

If you are trying to terminate the ipsec on a device behind the nat router, then you will have to configure a static on the router.

**Please rate posts you find helpful**

what i am trying to do is allow a visitor/vendor to phone home using ipsec vpn client on a router that is running nat/overload. i have the following configured in the router and applied to the internal(private)and external(internet facing) interfaces.

ip access-list extended ipsec

remark SDM_ACL Category=4

permit esp any any

permit ahp any any

i am running sdm (security device mgr on the 2811)

thanks for your support.

Am I getting this right?

- You have a visitor inside your network using a VPN Client.

- He has a IPSEC router with IPSEC NAT Transparrancy enabled at home.

- Your router is doing FW / NAT / PAT in between

If this is the case you should permit UDP IKE-NONE500 (i believe it is port 4500 (or 10000)) to travel through your router..

When using NAT Traversal, ESP is encaptulated i a UDP packet to be able to travel trough the NAT devices.

Hope This Helps

Greetings

Jarle

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: