cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
568
Views
0
Helpful
2
Replies

PIX VPN client with NAT

nkariyawasam
Level 1
Level 1

I have my PIX 515, outside interface has a private IP address. It is NATted to a public IP address at the internet router.

If I am using PIX VPN client at the other end to contact PIX, will htere be any issue due to NAT ?

2 Replies 2

thiland
Level 3
Level 3

Your VPN client would need to encapsulate IPSec traffic in UDP. You would need to port forward UDP/4500 (the default UDP encap port #) from the internet-facing router to the PIX firewall.

ehirsel
Level 6
Level 6

You will also need to enable nat transversal on the pix; it is off by default.

I believe that the command is this: isakmp nat-transversal