Solved

IPSec VPN connection from behind a PAT firewall?

Posted on 2003-10-22
6
2,230 Views
Last Modified: 2008-03-10
Hi folks,

I know that I cannot create a outbound PPTP-based VPN connection from behind my PAT firewall (Cisco PIX) without creating static mappings between the internal (private) and an external (public) address. Obviously this isn't feasible, since I would need to have a separate public address for everyone who needs/wants to make an outbound VPN connection, and I'd need to setup static mappings for each address.

However; can anyone confirm or deny whether this is possible when using IPSec to create the firewall connection?

Basically, I would like to have a way to allow people from behind my firewall to make a VPN connection to another office, ideally without 1-1 address mapping. I don't want to have a LAN-LAN VPN tunnel, I want it PC-LAN.

Thanks!
JP
0
Comment
Question by:JammyPak
  • 3
  • 2
6 Comments
 
LVL 16

Expert Comment

by:_nn_
ID: 9598957
I don't see how. IPSec needs UDP 500 and IP proto 50/51. In a sense, it's "IP-in-IP", so AFAIK, it can't work through a PAT.
0
 
LVL 3

Accepted Solution

by:
t1n0m3n earned 500 total points
ID: 9621266
Yes I use IPSec through NAT all the time.

The trick is to enable the "IPSEC over TCP" setting in the client that you are using, and make sure that it is enabled on the other side as well.
You can also use UDP instead of TCP.

Basically, the protocol 50 (and 51 if you are using AH) will get encapsulated in a TCP packet and look like normal TCP/IP traffic to the NAT device.

I have many contractors that use this type of connectivity today.
0
 
LVL 3

Expert Comment

by:t1n0m3n
ID: 9621269
BTW the default TCP port for IPSec over TCP is port 10000.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 3

Expert Comment

by:t1n0m3n
ID: 9621274
Basically, the protocol 50 (and 51 if you are using AH) will get encapsulated in a TCP packet and look like normal TCP/IP traffic to the NAT device.

NAT should read PAT
0
 
LVL 16

Author Comment

by:JammyPak
ID: 9629432
Hi folks, thanks for the responses.

t1n0m3n, I'll try this out and let you know how it goes!
0
 
LVL 16

Author Comment

by:JammyPak
ID: 9653739
Seems to work great - thanks!
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
google exe file 5 62
Standard Naming Convention Policy - Servers, Routers, Switches, Firewalls 3 59
VLAN Question 13 43
What is an ASP Table on a Cisco ASA? 3 15
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question