IPSec port forwarding w/ NAT traversal

xyyz

Diamond Member
Sep 3, 2000
4,331
0
0
here's a quick diagram:

*internet* ------ [cisco 831] ------ (pix) ------- *private network*

i've done the ipsec vpn setup on the pix, and i tested it on the network between the 831 and the pix; it works.

can someone tell me what ports/protocols/etc i need to forward on the 831 to the pix?

i know how to port forward, but i don't know if you can forward protocols right? i think i'll just need to let the router accept those protocols?

also, since the traffic is passing through a NAT to get to the pix, do i need to do enter any commands to prevent disruption?

finally, please please please stick on topic. i didn't ask if this was the best way to do it, or ask for another way to do it. i just want to know how to handle this particular situation.
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
If you just do straight NAT, meaning IP address to IP address, not PAT (port numbers) it should work on the 831. The PIX has more intelligence to deal with IPsec but it's easy in IOS. Search cisco.com for "ipsec NAT configuration".

It will depend somewhat on the VPN endpoints on what ports/protocols you need to be doing. If you're doing NAT traversal the actual tunnel traffic will be wrapped in a udp or tcp header (udp is the preferred wrapper) depending on configuration of ipsec.

-edit-
normal ipsec uses UDP port 500 for the initial phase/negotiation. Even if you just search cisco.com for "ipsec nat configuration" you'll get a TON of info.
 
Last edited:
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |