cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
685
Views
0
Helpful
5
Replies

Required Ports?

dkim777oig
Level 1
Level 1

I have following Ports required but when I enabled NAT-T on client side (I think server is ON by default)

It can't connect(no prompt for username) just hangs and time out.

protocol 50 and 51

udp 500

udp 4500

do I need more?

Again, It connects fine with NAT-T disabled, and no go with NAT-T enabled.

5 Replies 5

husycisco
Level 7
Level 7

Hi dae,

"I think server is ON by default"

I assume you are trying to establish VPN connection to a Cisco device correct? Then you should issue the following command to enable NAT-T on device

crypto isakmp nat-traversal 20

Regards

sorry, I meant to ask what are the required ports.

do I need any other ports other than what I've said in the first post?

thanks

4500 and 500 are enough for NAT-T over UDP. For NAT-T over TCP, you also need TCP port 10000

on PIX ADSM setting it doesn't differenciate UDP or TCP NAT-T.

which one am I enabled?

dae,

I cant remember the exact screen in ASDM, but to enable it, you type the following in CLI

cyrpto isakmp nat-traversal 20

This enables NAT-T and it uses UDP by default. To use TCP, you need the following command

isakmp ipsec-over-tcp port 10000

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: