<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec VPN Questions in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-vpn-questions/m-p/3231982#M1042353</link>
    <description>&lt;P&gt;1) For NAT-T to work both ends should be enabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/security-documents/how-does-nat-t-work-with-ipsec/ta-p/3119442" target="_blank"&gt;https://supportforums.cisco.com/t5/security-documents/how-does-nat-t-work-with-ipsec/ta-p/3119442&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) sounds like a capacity issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) DPD should be enabled on both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;
&lt;P&gt;Murali.&lt;/P&gt;
&lt;P&gt;~Impossible is often the untried&lt;/P&gt;</description>
    <pubDate>Thu, 14 Dec 2017 01:06:07 GMT</pubDate>
    <dc:creator>Murali</dc:creator>
    <dc:date>2017-12-14T01:06:07Z</dc:date>
    <item>
      <title>IPSec VPN Questions</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-questions/m-p/3231953#M1042351</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings !!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have some questions in my mind and I was hopeing if you guys can answer.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Say you have to create IPSEC VPN between two FW, but say FW 1 sit behind NAT device and you need to enable NAT-T on it but FW2 has direct connection to internet (it does not site behind NAT) , so if I think you dont need to enable NAT-T on FW2. Will it work if you have FW1 NAT-T enabled and FW2 no NAT-T ? Or do you have to enable NAT-T on both FWs, will it be a problem?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) If see message "Jun 09 12:11:32 [IKEv1]IP = X.X.X.X, Maximum concurrent IKE negotiations exceeded" &amp;nbsp; , when can we expect this message and if we can fix this error&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) If you enable DPD on on FW and on the other firewall if you disable DPD, will it cause issues for the tunnel or will it be ok.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maria&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:57:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-questions/m-p/3231953#M1042351</guid>
      <dc:creator>Lifeisbeautiful</dc:creator>
      <dc:date>2020-02-21T14:57:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec VPN Questions</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-questions/m-p/3231982#M1042353</link>
      <description>&lt;P&gt;1) For NAT-T to work both ends should be enabled&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportforums.cisco.com/t5/security-documents/how-does-nat-t-work-with-ipsec/ta-p/3119442" target="_blank"&gt;https://supportforums.cisco.com/t5/security-documents/how-does-nat-t-work-with-ipsec/ta-p/3119442&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) sounds like a capacity issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) DPD should be enabled on both sides.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;
&lt;P&gt;Murali.&lt;/P&gt;
&lt;P&gt;~Impossible is often the untried&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2017 01:06:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-questions/m-p/3231982#M1042353</guid>
      <dc:creator>Murali</dc:creator>
      <dc:date>2017-12-14T01:06:07Z</dc:date>
    </item>
  </channel>
</rss>

