Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

NAT-T question on ASA

I have an ASA that currently has about 100 IPSEC tunnels coming into it. NAT-T is not enabled on the ASA. We have a new customer coming on that is asking for us to enable NAT-T as apparently they have a NAT device on their side in between. My question is, if I enable it on our ASA, what does it do to all the tunnels that don't require it? Is there a way to only run it on this one new tunnel?

3 REPLIES

Re: NAT-T question on ASA

NAT-T is negotiated at Phase 1 IKE. If you have tunnels that do not require it, they will not use it.

HTH>

New Member

Re: NAT-T question on ASA

thanks. does anyone know if its possible to enable it for just the one tunnel, or does it only get enabled "globally"?

Re: NAT-T question on ASA

It's a global command - so no, you cannot enable on a per tunnel basis.

268
Views
0
Helpful
3
Replies