cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
30969
Views
5
Helpful
2
Replies

Ports used in IKE Phase 1

mahesh18
Level 6
Level 6

Hi everyone,

Need to confirm during IKE Phase 1

we use port UDP 500

IKE Phase 2 we use ports

ESP -50

NAT-T UDP 4500

TCP-1000 ESP -50
NAT-T UDP 4500
TCP-1000

Regards

Mahesh

1 Accepted Solution

Accepted Solutions

m.kafka
Level 4
Level 4

IKE phase 1 (main mode/aggressive mode) is udp src and dst 500

IKE phase 2 could be:

  • IP protocol 50 (ESP)
  • NAT-T is udp src (client) ephemeral dst (server) udp 4500
  • The tcp encapsulation found in the older VPN clients was src (client) ephemeral dst (server) tcp 10000 (10,000 in US resp. 10.000 in most of the other world)

    View solution in original post

    2 Replies 2

    m.kafka
    Level 4
    Level 4

    IKE phase 1 (main mode/aggressive mode) is udp src and dst 500

    IKE phase 2 could be:

    • IP protocol 50 (ESP)
    • NAT-T is udp src (client) ephemeral dst (server) udp 4500
    • The tcp encapsulation found in the older VPN clients was src (client) ephemeral dst (server) tcp 10000 (10,000 in US resp. 10.000 in most of the other world)

      Many thanks

      Regards

      MAhesh

      Getting Started

      Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: