It is as simple as this one, both DC and client routers are behind firewalls. I have done the routers config on both routers and both are identical.
At Data Center i am using Static (identity) nat on firewall for DC-RTR (10.27.59.243) address. There are two routers at client site and they are configured with 192.168.112.210 and 211 respectively. I don't have access to Client Firewall and the engineer said he has configured the static translation from 192 addresses to 10.128.14.75 and 76 respectively.
When i check the ISAKMP sa i can see the following.
192.168.112.210 10.27.59.243 MM_NO_STATE 0 ACTIVE 192.168.112.210 10.27.59.243 MM_NO_STATE 0 ACTIVE (deleted) 192.168.112.211 10.27.59.243 MM_NO_STATE 0 ACTIVE 192.168.112.211 10.27.59.243 MM_NO_STATE 0 ACTIVE (deleted) 10.27.59.243 10.128.14.76 MM_NO_STATE 10050 ACTIVE (deleted) 10.27.59.243 10.128.14.75 QM_IDLE 10051 ACTIVE
If i use the show ip nhrp i get the following
192.168.213.21/32 via 192.168.213.21 Tunnel0 created 17:15:14, expire 00:05:49 Type: dynamic, Flags: registered used NBMA address: 192.168.112.210 192.168.213.22/32 via 192.168.213.22 Tunnel0 created 17:15:52, expire 00:05:52 Type: dynamic, Flags: registered used NBMA address: 192.168.112.211
IP addresses in red are the real IPs configured on router's interface and are supposed to get NATTed behind 10.128.14.75 and 76 respetively.but i don't see it happening.
UDP/4500 is allowed on both firewalls for NAT-T. The only this on client FW is that it is running 9.1 IOS and we are running 8.2.
I am not sure if it is client FW which is doing the trick.
Login to the FXOS chassis manager.
Direct your browser to https://hostname/, and log-in using the user-name and password.
Go to Help > About and check the current version:
Check the current version availa...
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...