Hi. We are currently configuring an ASA5510 running v8.0(2). We have setup NAT traversal for ipsec using:
crypto isakmp nat-traversal 20
This works fine. The problem is, whenever I write the config (write mem) it doesn't retain this setting in the startup-config. A "show running-config" immediately after a reload contains the line:
no crypto isakmp nat-traversal
If I edit the config in a txt editor, and add "crypto isakmp nat-traversal 20", then copy it to startup-config, it works. This isn't sufficient though, as it only lasts until the next time the config is updated by a "write mem" command, whereby it is disabled again.
Is this a bug in 8.0(2)? Is there any way to add a persistent entry in the ASA config that is *always* retained when a "write mem" command is issued? Any help/advice appreciated.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...