Does NAT break IPSec?
Posted on 2009-04-08
I am trying to find a way to securely handle Microsoft Active Directory replication as well as other Microsoft networking traffic between 2 Windows Server 2003 systems. Ordinarily I would set up a site to site VPN using SonicWall or NetGear devices. However, I can't in this situation because one of my servers is a virtual server that is hosted at Triple8 networks. Thus, I have no way of deploying my own hardware based VPN.
I thought the best way to do this would be to set up IPSec Rules and Security Associations to handle all traffic between the 2 systems. When the policies and rules are disabled, I can successfully ping back and forth between the 2 systems which tells me that I have successfully set up the firewall rules on the side that I can control.
When I enable the policies and launch ping from the command prompt, I just see the message NEGOTIATING SECURITY over and over. When I examine the logs on both sides, I see several 541, 542, and 543 messages indicating successful starting and ending of security associations. I have actually tried numerous systems including Windows XP with different firewalls and networks and observed similar results.
The only system with its own direct public ip address is my virtual server at Triple 8. The other systems that I have tried are all behind firewalls and are NAT'd.
Any thoughts as to why I cannot get this to actually work? Is there a better way to accomplish my goal?