cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
542
Views
0
Helpful
1
Replies

VPn Issue

Kanwar
Level 2
Level 2

I like to know is it possible to initiate a vpn connection from behind the pix firewall without doing nat or one to one mapping. I am using microsoft client to connect to the vpn server. it works if I map my ip to the Public ip but If I use pat It does not work.

Thanks in advnace

1 Reply 1

michelcaissie
Level 4
Level 4

IPSEC protocols like esp and ah doesn't work well with PAT.

What you need is to do IPSec over UDP (if supported by your client-server vpn environment and enable NAT traversal in your PIX using the commands

isakmp nat-traversal 20

isakmp enable outside