Solved

IPSec-awareness NAT Spi-Matching Scheme

Posted on 2010-11-16
2
1,422 Views
Last Modified: 2012-05-10
How do I find out if my Router has IPSec-awareness NAT spi-matching scheme  . . . I am having issues getting a tunnel up between my Cisco 2811 and a ASA . . . logs show it is using NAT-Traversal (default) . . . but I see refernces to SPI Matching. If they are conflisting I can trouble shoot.
0
Comment
Question by:smartini67
2 Comments
 
LVL 5

Expert Comment

by:shubhanshu_jaiswal
ID: 34152653
Kindly post your configuration of router and asa....
0
 
LVL 28

Accepted Solution

by:
bgoering earned 500 total points
ID: 34160278
You might take a look at http://www.cisco.com/en/US/docs/ios/12_2t/12_2t15/feature/guide/ftsecnat.html

"SPI Matching
SPI matching is used to establish VPN connections between multiple pairs of destinations. NAT entries will immediately be placed in the translation table for endpoints matching the configured access list. This is available only for endpoints that choose SPIs according to the predictive algorithm implemented in Cisco IOS Release 12.2(15)T."

Do you multiple destinations on either the router or the firewall?
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now