NAT-T question.

Apr 13, 2005 1 Replies

Does NAT-T needed when remote vpnpoint is behind a device doing NAT or it is needed only if the device is not IPsec passthrough?



Sorry for newbie questions.



Alex.



If you only have one user behind the NAT box using IPsec and the NAT box supports IPsec passthrough then you don't need NAT-T, though you may prefer to use it depending on the quality of the IPsec passthrough support in the NAT box.

If you have multiple users behind the same NAT box all wanting to use IPsec then most (all?) NAT IPsec passthrough implementations will result in one or more of the IPsec connections failing unless the client turns on NAT-T.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required