Link to home
Start Free TrialLog in
Avatar of Sp0cky
Sp0cky

asked on

We set up an ipsec connection using a fortigate connectoid...and it works fine behind NAT..but will our MS L2TP Ipsec VPN work that same?

If not, why not?  Is there something that the fortigate may have that the MS solution does not to make it work with NAT?  Thx.
Avatar of prashsax
prashsax

It will not work.

The problem with NAT comes about because the NAT device must translates the source address, and might assign a new source port to maintain a table to be used in routing replies back to the originating host.

Here's what's happening:
The NAT device modifies an outgoing packet by changing the real source address, the address of the sending client, to that of the Internet routable address provided to the NAT device. When packets from the Internet return to the NAT device, it is able to modify the destination address (which arrives using the Internet routable address assigned as the source address of the outgoing packet). How does it know the new source address to use? It knows because it keeps a table of sources addresses and ports mapped to the assigned source address and ports it replaced in outgoing packets. It is able to match the incoming packets and modify the destination address and port. However, because of the built-in security mechanisms of IPSec such tampering with the address is not allowed, hence the packets are dropped. This is why a Win2K to Win2K VPN that must pass through a NAT device can only use PPTP
Avatar of Sp0cky

ASKER

I am being told this is not an issue whe nusing pre-shared key without ESP...Is this true?
Avatar of Sp0cky

ASKER

If IPSEC is not natable and PPTP has difficulties passing gre through service providors and or more than one client behind nat, then what good are VPN's?  This is confusing.
You can use IPSec with ESP.

This can easily pass thru any NAT in between the peers.

ASKER CERTIFIED SOLUTION
Avatar of prashsax
prashsax

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Sp0cky

ASKER

ok.  Thank you.