NAT-T is supported by cisco 831?

Feb 01, 2009 3 Replies
NAT-T is supported by cisco  831? open original image

Hi guys, sorry for my question but I'm newbie with Cisco routers .. I have to make a IPSEC VPN with two firewall Fortinet, among the firewall there is a Cisco router 831 with NAT. I know that IPSEC is work fine only if router support nat-t and i would like to know if i need confgigure something on 831 for make compliant.



Thanks very much Andrew


Hmmm. I did not know that NAT-T required special support in the NATing router. Seems that it might well.

formatting link
Best to check the feature navigator against your version. If you post the version someone might check.

formatting link

thanks, seems nat-t supported by my IOS 12.3(8r) version. Unfortunately VPN does not works,only with cisco router that among the firewall, the others vpn works fine :(

But there is a strange thing, I've seen in a table nat that VPN nat-t does not connect with port 4500 but only on 500:

Pro Inside global Inside local Outside local udp 88.xx.41.xx:500 172.16.10.250:500 79.xx.158.xx:500

Outside

79.xx.158.xx:500

Others VPN connect to udp port 4500

:(

Without NAT. UDP:500 is used for IKE then IP type 50 for ESP traffic

With NAT - ie NAT-T configured on IPSEC peers (Fortigate) and NATter detected in path UDP:500 is used for IKE then UDP:4500 for ESP traffic

You usually need to enable NAt-T on the firewalls. On cisco PIX/router it has to be specifically enabled. I forget the default on checkpoint but you can turn it off I think.

It seems that IKE detects the presence of a NATter and then chooses UDP:4500 if required.

I have used NAt-T a few times and it has just worked. It does seem as if complications might arise however.

formatting link
"IPsec-aware NATs can cause problems "

formatting link
page is effectively a nice list of links.

I would:-

- Recheck the configuration

- Have a shot at a software upgrade since there is no doubt that cisco have been fiddling with this. 12.3(8r) will be pretty old now.

- debug ip nat on the cisco is nice, log for every packet might just show up an anomaly.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required