cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
484
Views
0
Helpful
4
Replies

VPN through NAT

maller
Level 1
Level 1

Hello

This is my scenario:

Internet - router Cisco 836-- FW appli.

I've configured NAT in my router

Ports UDP 500,4500,2746

Ports TCP 256,264,1723

Portocol 50

It seems that works but in my router log I see some messages about ESP NAT translations.

*Mar 4 02:52:29.641: NAT: IPSec: inside host (172.0.0.16) is trying to open an ESP conn to 83.131.93.2, cannot process request from 172.0.0.16

*Mar 4 02:52:59.633: NAT: IPsec: using mapping to create outbound ESP IL=172.0.0.16, SPI=A395EEB3, IG=113.96.3.**

*Mar 4 02:52:59.637: NAT: IPSec: inside host (172.0.0.16) is trying to open an ESP conn to 83.***.66.2, cannot process request from 172.0.0.16

Are there messages right in an IPSEC NAT Process

thanks

4 Replies 4

pradeepde
Level 5
Level 5

After the connection and authentication completes, the client does not receive any traffic for over a minute while NAT cycles thru these messages:

*Mar 4 02:52:29.641: NAT: IPSec: inside host (172.0.0.16) is trying to open an ESP conn to 83.131.93.2, cannot process request from 172.0.0.16

*Mar 4 02:52:59.633: NAT: IPsec: using mapping to create outbound ESP IL=172.0.0.16, SPI=A395EEB3, IG=113.96.3.**

*Mar 4 02:52:59.637: NAT: IPSec: inside host (172.0.0.16) is trying to open an ESP conn to 83.***.66.2, cannot process request from 172.0.0.16

jackko
Level 7
Level 7

just wondering if you are doing port forward or 1-1 ip nat. with ip 50 (i.e esp), you'll need a 1-1 ip nat.

just wondering how you go.

georges.merhej
Level 1
Level 1

Hello Guys,

I'm facing the same problem on a 2811 router.

Did anyone find a solution for it?

Thank you.