08-09-2012 08:04 AM
Can an ASA initiate a L2L VPN over NAT-T behind a router?
The VPN can be successfully established when our third party start the connection but not when we start it from our end.
Many vendors don't support this scenario, I would like to know if Cisco do.
Solved! Go to Solution.
08-09-2012 09:30 AM
Yes that will work. The ASA can be behind a NAT as an IPSec-originater as well as an IPSec-responder. Of course the NAT hast to be configured properly if the ASA is the responder.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
08-10-2012 04:09 AM
Yes, that will work. If both ASAs have NAT-T enabled (which is the default) then there is no reason that it shouldn't work.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
08-09-2012 09:30 AM
Yes that will work. The ASA can be behind a NAT as an IPSec-originater as well as an IPSec-responder. Of course the NAT hast to be configured properly if the ASA is the responder.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
08-10-2012 02:49 AM
Thanks Karsten for your quick reply.
If the othe peer was another ASA with no NAT in front of it, would it be able to initiate the proposal?
08-10-2012 04:09 AM
Yes, that will work. If both ASAs have NAT-T enabled (which is the default) then there is no reason that it shouldn't work.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide