Solved

Site to Site VPN behind NAT

Posted on 2010-09-08
2
1,109 Views
Last Modified: 2012-05-10
I need to setup a site to site VPN between two location, one of the locations has my VPN appliance and ASA 5505 NAT-ed behind the ISP router

ISP----NAT-Router-----ASA5505----LAN

The NAT is a one to many NAT.
The Site to Site VPN will be an IPSEC vpn.

My questions is can i setup the point to point in these conditions? i'm pretty sure i will need to setup some port address translations if it can work, the question is which ports will i need?

Thanks
0
Comment
Question by:curwengroup
2 Comments
 
LVL 9

Accepted Solution

by:
Donboo earned 500 total points
ID: 33631255
Yes it can be done like that.

You need to PAT/NAT port udp 500 and 4500 and your Remote VPN concentrator must be setup for NAT-T VPN connections.
0
 
LVL 2

Expert Comment

by:slotb007
ID: 33660659
Exactly what Donboo said.

With NAT you need to enable NAT-T (Nat traversal).
Traffic is send over UDP port 500/4500.
IPSec can then travel over NAT...
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Preface Having the need * to contact many different companies with different infrastructures * do remote maintenance in their network required us to implement a more flexible routing solution. As RAS, PPTP, L2TP and VPN Client connections are no…
Sometimes, you want your microsoft VPN to route all the traffic to the remote network. Usually your employer network. This makes it possible to access all the nodes inside this remote LAN, even if they have no "public DNS" entries. To do so, you wo…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

746 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now