Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IPSec behind PIX

hello guys,

i have a particular problem with my VPN concentrator behind PIX. i am doing a PAT and all traffic goes out from everywhere being PATed properly. except my esp (protocol 50) traffic. i get this message. even though i can get to the internet using the same inside IP that the error message is talking about (show that the PAT works )

305006: portmap translation creation failed for protocol 50 src inside:X.X.X.X dst outside:X.X.X.X

2 REPLIES
New Member

Re: IPSec behind PIX

Have you tried enabling nat traversal on either the VPN concentrator or the pix?

New Member

Re: IPSec behind PIX

Hello

ESP does not use ports like UDP or TCP, devices doing PAT cannot handle it easily.

ESP will pass through devices doing PAT if the ESP packet is first encapsulated in UDP; UDP has ports, and the PAT-ing device knows how to translate it. My advice is to enable NAT transversal in your VPN concentrator.

Just curious – how are you receiving VPN sessions initiated from Internet? The usual setup involves a separate static translation in firewall for VPN concentrator.

Regards,

Cristian

124
Views
0
Helpful
2
Replies