<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: nat traversal  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1282192#M949041</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ipsec pass-throgh and NAT-T two different things - same family but diferent purposes, separate them to not get confused. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ipsec-pass-through  beside (inspection engine - which is another topic)  it opens up Ipsec VPN ports,  in earlier PIX versions 6.x or bellow you had to open up specific ipsec ports by access list instead so that your inside users could vpn outbound to other vpn gateways. In ASA 7.x above you no longer need to do acls to accomplish this, inspect ipsec-pass-through does it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1721168" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1721168&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for enabling nat-t, short answer simply allows the PIX/ASA  or IOS UDP 4500 the detection of  NAT devices between them and allow futher  negotiating UDP encap  ipsec packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Coun't explain it better here -  to get the picture read this entire link -  See number 4 ( the problem ) &lt;A class="jive-link-custom" href="http://www.ittc.ku.edu/~kpm/ipsec_udp_encap/" target="_blank"&gt;http://www.ittc.ku.edu/~kpm/ipsec_udp_encap/&lt;/A&gt;   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of other references - Read the RFC3947 and RFC3948&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3947.txt" target="_blank"&gt;http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3947.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3948.txt" target="_blank"&gt;http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3948.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Sep 2009 21:18:18 GMT</pubDate>
    <dc:creator>JORGE RODRIGUEZ</dc:creator>
    <dc:date>2009-09-16T21:18:18Z</dc:date>
    <item>
      <title>nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1282191#M949038</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;My company has 2 sites each configured with cisco asa5510 with vpn. Originally site A firewall is configured with only ipsec passthrough while site B is configured with both ipsec passthrough and nat traversal. Users at site B could vpn into site A but unable to access any resources at A. However from my home, i could vpn into site A and access network resources within site A. I then added nat-traversal to site A firewall to resolve the problem. Why is this so? Can someone also explain the difference between nat traversal and ipsec passthru? Thks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:40:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1282191#M949038</guid>
      <dc:creator>donnie</dc:creator>
      <dc:date>2020-02-21T11:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: nat traversal</title>
      <link>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1282192#M949041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ipsec pass-throgh and NAT-T two different things - same family but diferent purposes, separate them to not get confused. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ipsec-pass-through  beside (inspection engine - which is another topic)  it opens up Ipsec VPN ports,  in earlier PIX versions 6.x or bellow you had to open up specific ipsec ports by access list instead so that your inside users could vpn outbound to other vpn gateways. In ASA 7.x above you no longer need to do acls to accomplish this, inspect ipsec-pass-through does it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1721168" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1721168&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for enabling nat-t, short answer simply allows the PIX/ASA  or IOS UDP 4500 the detection of  NAT devices between them and allow futher  negotiating UDP encap  ipsec packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Coun't explain it better here -  to get the picture read this entire link -  See number 4 ( the problem ) &lt;A class="jive-link-custom" href="http://www.ittc.ku.edu/~kpm/ipsec_udp_encap/" target="_blank"&gt;http://www.ittc.ku.edu/~kpm/ipsec_udp_encap/&lt;/A&gt;   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of other references - Read the RFC3947 and RFC3948&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3947.txt" target="_blank"&gt;http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3947.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3948.txt" target="_blank"&gt;http://www.unix-ag.uni-kl.de/~massar/vpnc/docs/rfc3948.txt&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Sep 2009 21:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat-traversal/m-p/1282192#M949041</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-09-16T21:18:18Z</dc:date>
    </item>
  </channel>
</rss>

