cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
515
Views
5
Helpful
3
Replies

port open

Mary
Level 1
Level 1

I was told to open both ipsec phase 1 and phase 2 port, may I know the command to open the port? thanks

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

What device are you doing this on?

 

Generally speaking you need to allow ip protocol 50 and 51 as well as udp port 500. 

+5 Marvin. I think udp/4500 as well for nat-t

Right -the udp 4500 is only necessary if there’s a device between the tunnel endpoints doing NAT. 

 

Protocol 50 - ESP (Encapsulating Security Protocol)

Protocol 51 - AH (Authentication Header)

udp/500 - ISAKMP (Internet Security Association and Key Management Protocol)

udp/4500 - NAT-T (Network Address Translation - Traversal)