cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1308
Views
0
Helpful
3
Replies

RVS4000 ISAKMP Nat Problem

oliviersabrie
Level 1
Level 1

Hi there,

I'm currently dealing with a weird problem on a Cisco RVS4000.

I'm tring to connect to a IPSEC VPN Gateway (NETASQ) located on the lan side of the RVS4000.

I'm using Greenbow vpn client on the WAN side of the RVS4000

Basicaly i'm trying to get through the RVS

My VPN config is ok because i tested it on the lan side of the RVS

The RVS is configured like this:

NO VPN configured.

Block WAN Request :OFF

FIREWALL,IPS,DDOS are OFF

NAT forwarding on for UDP 500 and 4500 directed from the wan to the ip of the VPN gateway

Seems right because iv managed to do this with other routers (different brands) on another site

I've wiresharked my vpn client and i keep getting ICMP destination unreachable (PORT UNREACHABLE) after my ISAKMP launching packet.

Can the RVS nat these ports ?

3 Replies 3

temesvarig
Level 1
Level 1

I have the exact same annoying problem.

Could someone from the vendor advise or confirm this as a bug?

I've managed to discover the trick. These two ports are some kind of reserved for the cisco vpn system. You can fool this by nating These two ports to a different value on the wan side.

wan --700--470 ---CISCO --- 500- 4500 ---YourVpnequipement

I think this may be a workaround for a web server port, but not a solution for VPN ports.