02-05-2004 03:06 AM - edited 02-20-2020 11:13 PM
I have trawled through much documentation but cannot find a definitive answer to a basic question so I hope that one of you 'out there' can. Does (and if so which sw release) a pix support ipsec over udp (as per Cisco vpn client)? The pix being the tunnel endpoint.
The background is that I am trying to get a vpnclient behind a MS ISA server to establish a tunnel to a remote pix and failing. MS point to the article about the Cisco Concentrator 3300, with the latest firmware updates. My testing seems to indicate that the PIX in question does support it, since in one configuration not involving ISA but with client access through another PIX involving NAT seems to work just fine.
Many thanks any help you can provide.
Solved! Go to Solution.
02-11-2004 08:23 AM
PIX Firewall Version 6.3 provides a feature called "Nat Traversal,that is UDP Encapsulation of IPsec Packets.
Use the following command to enable NAT-T
isakmp nat-traversal [natkeepalive]
default natkeepalives is 20 sec. 10-3600 is the range
NAT traversal (NAT-T) supports both static and dynamic crypto maps.
Cihan
02-11-2004 07:03 AM
Currently PIX does not support IPSec over UDP.
02-11-2004 08:23 AM
PIX Firewall Version 6.3 provides a feature called "Nat Traversal,that is UDP Encapsulation of IPsec Packets.
Use the following command to enable NAT-T
isakmp nat-traversal [natkeepalive]
default natkeepalives is 20 sec. 10-3600 is the range
NAT traversal (NAT-T) supports both static and dynamic crypto maps.
Cihan
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide