Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


IPSec over NAT-T

Dec 31,2009 by alperen

image

IPSec over NAT-T

NAT Traversal (NAT-T) allows IPSec peers to establish a connection through a device using NAT. NAT-T accomplishes this by encapsulating IPSec traffic in UDP datagrams, thereby providing NAT devices with needed port information. NAT-T technology autodetects any NAT devices and only encapsulates IPSec traffic when necessary.

The VPN 3002 hardware client uses NAT-T by default and requires no special configuration. The remote-access VPN client first attempts NAT-T, and then, if a NAT device is not autodetected, uses IPSec over UDP. The UDP packets allow IPSec traffic to pass through firewalls that would normally reject and discard it.

To use NAT-T, both the VPN Client and the VPN hardware device must meet the following requirements:

VPN Concentrator implementations of NAT-T support IPSec peers behind a single NAT/PAT device, under the following limitations:

  • One LAN-to-LAN connection

  • Either a single LAN-to-LAN connection or multiple remote access clients, but not a mixture of both

  • One Microsoft L2TP/IPSec client, which can support other remote access clients and one L2TP/IPSec client


1996 times read

Related news

» NAT Transparency
by alperen posted on Dec 31,2009
» IPSec over TCP
by alperen posted on Dec 31,2009
» The VPN 3002 in the Network
by alperen posted on Nov 19,2009
» IPSec over UDP
by alperen posted on Dec 31,2009
» Setting IPSec Defaults
by alperen posted on Nov 14,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author