cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
334
Views
0
Helpful
1
Replies

VPN Tunnel trough 3rd Party Firewalls

Patrick Werner
Level 1
Level 1

Hello Community.

As i know VPN doenst work well with NAT and PATon 3rd Party Firewalls.

We have two site every site has a single IP Adress in the Internet, every Site has a Vigor Draytek Firewall. The ASA's are direct behind the Vigor Drayteks.

                 <--------------------------------- VPN Tunnel ------------------------>

Site1 -> ASA -> Draytek Vigor -> INTERNET -> Draytek Vigor -> ASA -> Site 2

Is that possible, will that be stable ?

Thanks patrick

1 Accepted Solution

Accepted Solutions

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Patrick,

I would say that you could use NAT-Traversal to make it happen.

As you already know ESP/AH do not have any ports so you cannot use them with PAT, that is why you must use NAT-T

Regards,

Remember to rate all of the helpful posts

Julio Carvajal

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Patrick,

I would say that you could use NAT-Traversal to make it happen.

As you already know ESP/AH do not have any ports so you cannot use them with PAT, that is why you must use NAT-T

Regards,

Remember to rate all of the helpful posts

Julio Carvajal

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card