Header
Home | Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections
Syndication


Blogroll:

||||| ALL Cisco-Network ARTICLES |||||  
CCIE Journey,
The CCIE Journey,


NAT Transparency

Dec 31,2009 by alperen

image

NAT Transparency

The IPSec NAT Transparency feature deals with the many known incompatibilities among NAT and IPSec. Before IPSec NAT Transparency, a standard IPSec VPN tunnel would fail if one or more devices were implementing NAT or PAT anywhere in the delivery path. The various forms of this feature make NAT IPSec-aware, making it possible for remote access users to use secure IPSec tunnels to home gateways.

The Configuration | System | Tunneling Protocols | IPSec | NAT Transparency screen, shown in Figure 16-12, makes configuring NAT Transparency possible. NAT transparency can take any of the three following forms:

  • IPSec over TCP

  • IPSec over NAT Traversal (NAT-T)

  • IPSec over UDP

    Click To expand
    Figure 16-12: Configuring IPSec NAT Transparency

The VPN Concentrator series of devices can simultaneously support VPN tunnels using standard IPSec, IPSec over TCP, NAT-Traversal, and IPSec over UDP, depending on the requirements of the client with which it’s exchanging data. The VPN 3002 hardware client, while supporting only one tunnel at a time, can also connect VPN tunnels using standard IPSec, IPSec over TCP, NAT-Traversal, or IPSec over UDP. The order of precedence is as follows:

  • When enabled, IPSec over TCP takes precedence over all other IPSec implementations.

  • When both NAT-T and IPSec over UDP are enabled, NAT-T takes precedence.

Figure 16-13 shows the VPN Client software properties screen used to set the features. If TCP is selected, the port number box would be enabled.


496 times read

Related news

» IPSec over NAT-T
by alperen posted on Dec 31,2009
» IPSec over TCP
by alperen posted on Dec 31,2009
» IPSec over UDP
by alperen posted on Dec 31,2009
» Configure IPSec Backup Servers—VPN 3002 Client
by alperen posted on Nov 30,2009
» VPN, IPSec Encryption, and QoS Support
by alperen posted on Sep 10,2009
Did you enjoy this article?
(total 0 votes)

comment Comments (0 posted) 

More Top News
CCSP-Cisco Certified Security Professional
Most Popular
Most Commented
Featured Author