cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
614
Views
0
Helpful
3
Replies

Is it possible to forward UDP(6061,1970)protocol using IPsec VPN between two sites

eahmed007
Level 1
Level 1

Dear All ,

              Can anyone tell me that how to forward protocol udp using IPSec VPN between two sites. I have configured IPsec VPN in router between multiple site using Hub-Spoke Topology .Clients has one sotfware which support user-define protocol Udp(6061,1970) and protocol should be forward from Multiple sites to use the Application.So My query is that forward protocol would work using IPsec VPN.

I am eagerly waiting for your reply.It would be highly appreciated if you help me on this issue.

Thanks and regards...

Erfan

3 Replies 3

Hi Erfan,

As long as the udp flow is:

--- part of interesting traffic for vpn.

--- Unicast (in case of non-gre ipsec tunnel, Else ignore this point)

--- allowed by access-lists applied on internal lan interfaces of the routers

--- nat-exempted (if static port forward is configured, make sure that it is nat-exempted)

i do not think there is anything else that would stop the flow over vpn.

Let us know if you if you have any query on this.

Regards,

Praveen

Hi Praveen,

                    Thanks for your reply and help.I want to mention the details information for this topology.client is having one Server with one Application software which is responsed using udp protocol 6061 .If  I configure IPSec VPN among multiple Branch with Head office using router,then is it possible to forward UDP user define  port 6061 .Because i have to forwad the protocol from branch router to use the Application Server where as I have to configured ip helper-address in Head Office router for branch's Client PC ip address.Because this software works under Server -Client environment.

My question is that would user-define 6061 UDP protocol work through IPSece-VPN.

I am eagerly waiting for your valuable comments and assistance.

Thanks and regards...

Erfan

Hi,

Praveen has answered your question I think.

One remark though,  what has ip helper-address got to do with client-server relationship? It is used to transform broadcasts blocked by routers into unicasts.

Regards.

Don't forget to rate helpful posts.