Cisco Systems Port Forwarding / VPN Pass-Thru on a Cisco 2800

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Port Forwarding / VPN Pass-Thru on a Cisco 2800 Rob 08-30-06
Posted by Rob on August 30, 2006, 3:20 pm
Please log in for more thread options
I have a Cisco 2800 that is being used as a firewall. When I am behind
it and NATing to the Internet I am unable to VPN out to any VPN servers
because IPsec does not go accoss a NAT with out port forwarding. I am
trying to find out how to turn on port forwarding so that I can VPN to
remote locations. Any help would be much appreciated. Thanks


Posted by Igor Mamuzic on August 31, 2006, 10:09 am
Please log in for more thread options
Do you use IPSec vpn that wraps traffic in UDP packets? If so, UDP packets
will be NATed as all other UDP traffic and you'll be able to connect trough
this router onto another VPN server. This is default option if you use Cisco
EasyVPN and/or Cisco VPN clients. It works in my case and I also use 2800
ISR. The only additional thing to do is to open udp ports 500 and 4500 (src
and dst ports) in both directions (inbound and outbound), as well as esp and
ah traffic. Of course VPN server on another end must also be accessible from
the Internet by these udp ports.

Best Regards,
Igor


>I have a Cisco 2800 that is being used as a firewall. When I am behind
> it and NATing to the Internet I am unable to VPN out to any VPN servers
> because IPsec does not go accoss a NAT with out port forwarding. I am
> trying to find out how to turn on port forwarding so that I can VPN to
> remote locations. Any help would be much appreciated. Thanks
>



Similar ThreadsPosted
Port Forwarding / VPN Pass-Thru on a Cisco 2800 August 30, 2006, 3:20 pm
Cisco 2800 port state changes September 8, 2008, 10:41 pm
Port Forwarding with Cisco 871?? September 25, 2005, 12:58 pm
cisco pix 515 port forwarding - NOT possible? hard to believe.. July 27, 2005, 12:23 am
Cisco 871 router port forwarding July 12, 2006, 8:41 pm
Cisco PIX 501 port forwarding trouble September 24, 2006, 10:32 am
port mapping or forwarding on Cisco Pix 506E August 5, 2005, 1:30 pm
Port forwarding from cisco 2600 to ASA-5510 July 20, 2006, 10:23 am
Cisco 2600 + DSL + Cable -> Failover and port forwarding July 2, 2008, 12:47 am
Cisco PIX and RSA passthru - What ports need opening February 15, 2007, 9:52 pm
Port forwarding February 2, 2006, 3:05 pm
Port forwarding help? June 4, 2006, 10:23 pm
Need help Port forwarding on PIX 501 September 14, 2006, 9:18 am
Port 21 forwarding on PIX 501 September 15, 2006, 11:56 pm
PIX Port Forwarding November 15, 2006, 2:42 pm