cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
671
Views
0
Helpful
2
Replies

LAN to LAN VPN problum because of NAT-T

mustafa.mail
Level 1
Level 1

I am using VPN Concentrator 3030, with image 4.1.7.D. I configured remote access & LAN-to-LAN VPN on this concentrator. Now because of my remote access users have a problem to access VPN through NAT/PAT, I enable a NAT-T. (In Configuration | Tunneling and Security | IPSec | NAT Transparency). I open a UDP port 4500 on my firewall because My concentrator is behind the Firewall. Now my all the Remote access clients are working fine through NAT-T.

Also I have a some running LAN-to-LAN van connection, which is terminating on different peer devices (Router, Concentrator).. Now I didn't enable a NAT-T on any of the LAN-to-LAN Connection. But still my LAN-to-LAN connection is first trying to check the NAT devices. Why my LAN-to-LAN connection is first checking for NAT-T even I didn't enable NAT-T on LAN-to-LAN connection? Now beacuse of NAT-T, my LAN-to-LAN Connection is not able to established because NAT-T detect local device is behind the NAT. How can I resolve this problum? After disabling NAT-T my LAn-to-LAn VPN is working fine.

Thanks,

Mustafa

2 Replies 2

ehirsel
Level 6
Level 6

On the 3030 go to Configuration | Tunneling and Security | IPSec LAN-to-LAN | Add or Modify Screen and insure that the NAT-T option is not checked for all your lan-to-lan connections.

Let me know what you find.

Hi,

Yes, In LAN to LAN configuration, NAT-T option is not checked.

Regards,

Mustafa

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: