cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
334
Views
0
Helpful
1
Replies

PIX NAT-T with W2K client

keithl
Level 1
Level 1

I am trying to set up a PIX501 so that an outside W2K mobile user can IPSEC/L2TP into the "inside". I'm using PSK.

It works perfectly without a NAT box in between, but when I have to cross NAT (using NAT-T), phase 2 negotiation fails. I have enabled NAT-T in the PIX and it is always enabled in MS. I also don't think that this is a port blocking or compatible policy issue.

I've found the most likely reason. During phase 2 negotiation, the Microsoft client adds a payload "ID_FQDN" which the PIX rejects ("unknown src id_type 2"). MS client keeps retrying but PIX keeps rejecting.

MS client does not send this when NAT-T is not required. It only sends it when a NAT device is detected in the path (through the NAT-D exchange).

This seems like a simple incompatibility between MS's interpretation of NAT-T RFCs and Cisco's.

1) Is this the problem?

2) How do I work around it?

TIA

Keith

1 Reply 1

umedryk
Level 5
Level 5

Hi Keith,

Tunnel establishment fails with L2TP/IPSec client with NAT-T

Hope this helps

Review Cisco Networking for a $25 gift card