Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Does NAT break IPSec?

Posted on 2009-04-08
3
Medium Priority
?
405 Views
Last Modified: 2012-05-06
I am trying to find a way to securely handle Microsoft Active Directory replication as well as other Microsoft networking traffic between 2 Windows Server 2003 systems.  Ordinarily I would set up a site to site VPN using SonicWall or NetGear devices.  However, I can't in this situation because one of my servers is a virtual server that is hosted at Triple8 networks.  Thus, I have no way of deploying my own hardware based VPN.

I thought the best way to do this would be to set up IPSec Rules and Security Associations to handle all traffic between the 2 systems.  When the policies and rules are disabled, I can successfully ping back and forth between the 2 systems which tells me that I have successfully set up the firewall rules on the side that I can control.

When I enable the policies and launch ping from the command prompt, I just see the message NEGOTIATING SECURITY over and over.  When I examine the logs on both sides, I see several 541, 542, and 543 messages indicating successful starting and ending of security associations.  I have actually tried numerous systems including Windows XP with different firewalls and networks and observed similar results.

The only system with its own direct public ip address is my virtual server at Triple 8.  The other systems that I have tried are all behind firewalls and are NAT'd.

Any thoughts as to why I cannot get this to actually work? Is there a better way to accomplish my goal?

Thank you,

Angela
0
Comment
Question by:amozart
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 4

Accepted Solution

by:
dj_relentless earned 500 total points
ID: 24104530
It can work from behind nat but not all nat's are equal. I've seen to work and not work depending on the hardware.
So in your situation you could put a test server on the dmz of your network and test it. Then at least you will know which side is causing the problem.
0
 
LVL 4

Assisted Solution

by:StefanKittel
StefanKittel earned 500 total points
ID: 24104630
Hello,

in general NAT modifies the destination and/or source of the packet so IPSec throws the packet away because it is modified.
Many NAT-router have a IPSEC-passthrough. But not all and not for all situations.

Because you can't remove or modify the NAT-Router your possibilites are limited.

May be you can use a different vpn software to connect. maybe openvpn.

Stefan
0

Featured Post

Learn Veeam advantages over legacy backup

Every day, more and more legacy backup customers switch to Veeam. Technologies designed for the client-server era cannot restore any IT service running in the hybrid cloud within seconds. Learn top Veeam advantages over legacy backup and get Veeam for the price of your renewal

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
Two types of users will appreciate AOMEI Backupper Pro: 1 - Those with PCIe drives (and haven't found cloning software that works on them). 2 - Those who want a fast clone of their boot drive (no re-boots needed) and it can clone your drive wh…
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question