cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1835
Views
0
Helpful
6
Replies

SPI Matching

rajesh.aesi
Level 1
Level 1

How to disable SPI matching on IOS 15.X ?

 

I tried to give command: no crypto ipsec nat-transparency spi-match

but then also in "show ip nat translation" I am getting SPI instead of port no

6 Replies 6

Francesco Molino
VIP Alumni
VIP Alumni
Hi

What's your goal?
Why not using nat-t auto detection and auto negotiation with the command:
crypto ipsec nat-transparency udp-encapsulation

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Hi

 

I am just experimenting.

I am also confused weather SPI match is enabled by default or not.

Please check attach image.1.png

If you do a show run all | inc crypto ipsec nat-transparency , you'll see which one is by default. Normally it should be UDP nat-t.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

After disabling both

Thanks a lot for prompt response.

 

no crypto ipsec nat-transparency udp-encap

no crypto ipsec nat-transparency spi-match

I am getting below output on my NAT device, which clearly indicating instead of port no its using SPI though I have disabled spi-match

 

S2S_4.png

You can preserve the port if you want but it won't react correctly on some vpn gateways.
Look at this doc: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipaddr_nat/configuration/xe-16/nat-xe-16-book/iadnat-applvlgw.html

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question