cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
530
Views
0
Helpful
2
Replies

VPN Drops after phase 2 establishment

simran2642
Level 1
Level 1

Hi,

I have a Site to Site VPN between ASA and ForeFront TMG. I am able to establish the tunnel. However, the moment pahse 2 is established, the very next second tunnel is dropped.

On ASA, I get to see... received delte SA message

And on ForeFront Iget to see the below message:

tunnel model in two NAT setting is not supported.

Both the VPN peers are behind a NAT device.

Please help.

2 Replies 2

Julio Carvajal
VIP Alumni
VIP Alumni

Hello,

I think you need to configure Nat traversal on the ForeFront TMG side.

Regards,

Julio

Do rate all the helpful posts

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

NAT - T is already enabled...