01-20-2006 05:06 AM - edited 02-21-2020 02:12 PM
Hi there- anyone have a sample config for Nat traversal on a PIX (501) running 6.3?
Sadly, I only have a single public IP, used by my router, and the ISP doesn't support PPPoE. So, my layout looks like this:
(ISP)---(Router)--(PIX)--LAN
As a result, I'm having to do RFC NAT on both the router and the PIX, and this is causing problems with terminating a PPTP (Windows) VPN on the PIX.
Anyone have a sample config that would help with this?
Cheers!
01-20-2006 06:49 AM
...just put this in your usual vpn config:
isakmp nat-traversal 20
this encapsulates ipsec into udp port 4500
...if it's a site-to-site vpn make sure it's on both pixes
01-21-2006 02:07 AM
Cheers Monkeyboy, I'll try this out as soon as I can.
Interesting command- I wonder what the "20" denotes?
Thanks
01-21-2006 02:29 AM
Just found out- 20 is a timer.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide