cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
331
Views
0
Helpful
4
Replies

VPN outbound and NAT Pools

randyclark
Level 1
Level 1

We are using NAT addressing on our internal LAN. In order for someone to use IPSEC to VPN to their home network does the client on our network have to have a NAT address with a static outside address or will it work from a NAT Pool?

4 Replies 4

acomiskey
Level 10
Level 10

It depends whether or not remote end supports NAT-T (nat-traversal). This will allow ipsec and PAT to work together.

What we have on our side is the following.

Private IP ----> ASA5520-->NAT POOL-->Internet.

It would be up to the client to make the remote end work. All I have to know is if the client will work through our NAT Pool without making an static entry. Save opening the IPSEC port for that network range. Also would it require any by direction ports to be opened.

sorry, was thinking pat

Hi Randy,

Since the "fixup protocol esp" command is no longer supported with ASA. The only correct way to make ASA IPSec passthrough and to get it to work through Natting is, the headend device should be NAT-T compatible.

In other words, the headend device and the client should support NAT-T and it should be enabled on both of them.

It doesn't matter if you use NAT pool or PAtted ip address, as long as you have NAT-T enabled.

It would work.

*Please rate if helped.

-Kanishka

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: