cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
437
Views
0
Helpful
4
Replies

lan-to-lan issue between VPN3000 and IOS with NAT-T

morgsizun
Level 1
Level 1

I configured a lan-to-lan between my concentrator and an IOS router .

Everything is OK when my partner establishes the connection but i'm unable to do it.

When I uncheck "IPSec over NAT-T" on my VPN3000 then i can establish the tunnel.

Any idea?

4 Replies 4

a.kiprawih
Level 7
Level 7

Hi,

Use NAT-T if you have PIX/ASA. Your setup is direct lan-to-lan from VPN3K to a router.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a00801f0f0c.shtml

Rgds,

AK

Thanks for your help,

but I need to keep NAT-T activate on my concentrator for other connections (lan-to-lan and client) and that's my problem (IPSec NAT-T is unchecked in my lan-to-lan configuration).

Regards,

Morgan

Hi,

If you want to use NAT-T for other LAN-to-LAN & client and need to disable for specific this IOS LAN-to-LAN, then on other end of peer router use following command.

"no crypto ipsec nat-transparency udp-encapsulation".

So Now other end of the router will not use NAT-T, so both end will never agreed to use NAT-T and this tunnel will never use NAT-T.

Thanks,

Mustafa

Thanks Mustapha,

we tried to use the command:

"no crypto ipsec nat-transparency udp-encapsulation"

but nothing happenned (i think it was the 'by default config')

So we used the following command to come back:

"crypto ipsec nat-transparency udp-encapsulation"

and then i saw request on UDP 4500 and we were both unable to establish the tunnel.

It seems that the gateways cannot negotiate NAT-T!

Any Ideas?

Thanks,

Morgan

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: