<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nat traversal in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/3872855#M531411</link>
    <description>&lt;P&gt;Hi Varrao,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, does NAT-T will cause any issues while establishing phase-1 tunnel between the end-clients ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my scenario, I could see the Tunnel got established but I do not see any Tx and Rx bytes under the VPN Session.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance..&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2019 06:12:37 GMT</pubDate>
    <dc:creator>thanghadurai.shanmughem1</dc:creator>
    <dc:date>2019-06-14T06:12:37Z</dc:date>
    <item>
      <title>Nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772376#M531406</link>
      <description>&lt;P&gt;What is the exact use of nat traversal .Can anyone explain with a scenario.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772376#M531406</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2019-03-11T21:22:28Z</dc:date>
    </item>
    <item>
      <title>Nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772377#M531407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prashant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I woudl be able to explain you in detail, if you can let me know what are you trying to accomplish on the device and with whihc device are you working with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 06:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772377#M531407</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-09T06:25:12Z</dc:date>
    </item>
    <item>
      <title>Nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772378#M531408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we are using asa 5520 in our environment.I&amp;nbsp; am&amp;nbsp; facing a problem ie&amp;nbsp; able to connect to vpn from outside network to lan but not able to take a remote of lan pc from particular network connection (airtel isp).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But when i try this from other service provider like reliance i am able to take remote.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 06:52:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772378#M531408</guid>
      <dc:creator>prashantrecon</dc:creator>
      <dc:date>2011-09-09T06:52:05Z</dc:date>
    </item>
    <item>
      <title>Nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772379#M531409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Prashant,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;&lt;TABLE class="messageDiv"&gt;&lt;TBODY&gt;&lt;TR class="msg"&gt;&lt;TD class="msgText"&gt;&lt;SPAN style="font-family: Verdana; font-size: 10pt;"&gt;this is under the VPN Profile ur&amp;nbsp; connecting to on the transport tab&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="timeStamp"&gt;12:30 PM&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="msg seperator_dotted"&gt;&lt;TD class="msgText"&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2264331"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2264331&lt;/A&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="timeStamp"&gt;12:31 PM&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="msg seperator_dotted"&gt;&lt;TD class="msgText"&gt;&lt;SPAN style="font-family: Verdana; font-size: 10pt;"&gt;by default on ASA NAT-T is&amp;nbsp; enabled&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD class="timeStamp"&gt; &lt;SPAN style="display: none;"&gt;12:32 PM&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR class="msg seperator_dotted"&gt;&lt;TD class="msgText"&gt;&lt;SPAN style="color: #000000; font-size: 10pt;"&gt;crypto isakmp&amp;nbsp; nat-traversal is the command&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P&gt;If a remote client is coming from a direct public ip address.. like a publically hosted server, then it connects over the tunnel like the regular tunnel establishes.. over UDP port 500, but if a client comes from behind a NATd ip address.. like airtel ADSL modem.. where u have a priv ip address.. but ISP PATs/NATs it.., then it connects over UDP 500.. but is encapsulated by another header.. the NAt-T header.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;and it communicates over UDP 4500...&amp;nbsp; then on the headend device.. like ASA you need to have NAT-T enabled&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when u have NAT-T enabled.. both NATd clients and clients with public ip will be able to connect &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but if u dont then only clients wih public ip will b able to conenct&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and also on the VPN client.. u need to have a check on&amp;nbsp; &lt;BR /&gt;Enable Transparent Tunneling&amp;nbsp; &lt;BR /&gt;and the radio button should be selected for IPSEC over UDP (NAT/PAT) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is under the VPN Profile ur connecting to on the transport tab &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2264331"&gt;http://www.cisco.com/en/US/docs/security/asa/asa83/command/reference/c5.html#wp2264331&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;by default on ASA NAT-T is enabled&amp;nbsp; &lt;BR /&gt;crypto isakmp nat-traversal is the command &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Sep 2011 07:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1772379#M531409</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-09-09T07:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/3872847#M531410</link>
      <description>&lt;P&gt;Hi Varrao,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, does NAT-T will cause any issues while establishing phase-1 tunnel between the end-clients ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my scenario, I could see the Tunnel got established but I do not see any Tx and Rx bytes under the VPN Session.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance..&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 05:35:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/3872847#M531410</guid>
      <dc:creator>thanghadurai.shanmughem1</dc:creator>
      <dc:date>2019-06-14T05:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/3872855#M531411</link>
      <description>&lt;P&gt;Hi Varrao,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case, does NAT-T will cause any issues while establishing phase-1 tunnel between the end-clients ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my scenario, I could see the Tunnel got established but I do not see any Tx and Rx bytes under the VPN Session.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in Advance..&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 06:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/3872855#M531411</guid>
      <dc:creator>thanghadurai.shanmughem1</dc:creator>
      <dc:date>2019-06-14T06:12:37Z</dc:date>
    </item>
  </channel>
</rss>

