Nat Traversal on 3725

Nat Traversal on 3725

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Nat Traversal on 3725 musiknut 04-25-2008
Posted by on April 25, 2008, 9:24 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all,
my company already has a pair of routers (3725) at head office
and several branch sites using 1801s. The small branches use ADSL and
hence have public fixed IP addresses. Three are the usual GRE tunnels
encrypted with IKE/IPSEC. The 1801s use Transport Mode (not Tunnel
Mode).

What I've been asked is, if a mobile branch could be put together. The
same 1801 will be used with the same encrypted GRE tunnel but it will
be behind an ADSL router and so NAT'd. I know I have to configure NAT
traversal and have read -
http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/htmipmar.html#wp1054243
My question is, can I enable NAT traversal on the head office without
affecting other tunnels that don't require it?

Alternatively, I know that Nokia VPN boxes (Sadly dicontinued) and
ASAs can use a management proxy for dynamically addressed sattelite
nodes. Can this also be done with Cisco boxes?

BR
Musiknut

Spring Sale Save 20% Banner - Sale Ended 5/3/07 So Updated to NonPromo Ad
Posted by on April 25, 2008, 9:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options
On 25 Apr, 15:24, musik...@gmail.com wrote:
> Hi all,
> =A0 =A0 =A0 =A0my company already has a pair of routers (3725) at head off=
ice
> and several branch sites using 1801s. The small branches use ADSL and
> hence have public fixed IP addresses. Three are the usual GRE tunnels
> encrypted with IKE/IPSEC. The 1801s use Transport Mode (not Tunnel
> Mode).
>
> What I've been asked is, if a mobile branch could be put together. The
> same 1801 will be used with the same encrypted GRE tunnel but it will
> be behind an ADSL router and so NAT'd. I know I have to configure NAT
> traversal and have read -http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11=
/htmipmar.html#wp105...
> My question is, can I enable NAT traversal on the head office without
> affecting other tunnels that don't require it?
>
> Alternatively, I know that Nokia VPN boxes (Sadly dicontinued) and
> ASAs can use a management proxy for dynamically addressed sattelite
> nodes. Can this also be done with Cisco boxes?

My (very limited but perhaps sufficient in this case) understanding
is that NAT-T is "negotiated" (or maybe discovered is better?) if
enabled
and will not affect non NATed links.

I am sure this it works OK since I have some Pixes doing that
at present.

If you do not know the IP address of the remote site in advance
you may have to use DMVPN.

Whether the 3725 will run a sufficiently recent IOS
to have DMVPN I don't know.

Here is a pix (6.4) doing NAT-T (udp encaps) and non NAT-T

sh cry ip sa | inc settings|peer
current_peer: x.x.x.22:500
in use settings =3D{Tunnel, }
in use settings =3D{Tunnel, }
current_peer: x.x.x.74:4500
in use settings =3D{Tunnel UDP-Encaps, }
in use settings =3D{Tunnel UDP-Encaps, }
current_peer: x.x.x.24:500
in use settings =3D{Tunnel, }
in use settings =3D{Tunnel, }

Posted by Darren on April 25, 2008, 10:20 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Bod43@hotmail.co.uk wrote:
> On 25 Apr, 15:24, musik...@gmail.com wrote:
>> Hi all,
>> my company already has a pair of routers (3725) at head office
>> and several branch sites using 1801s. The small branches use ADSL and
>> hence have public fixed IP addresses. Three are the usual GRE tunnels
>> encrypted with IKE/IPSEC. The 1801s use Transport Mode (not Tunnel
>> Mode).
>>
>> What I've been asked is, if a mobile branch could be put together. The
>> same 1801 will be used with the same encrypted GRE tunnel but it will
>> be behind an ADSL router and so NAT'd. I know I have to configure NAT
>> traversal and have read
-http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/htmipmar.html#wp105...
>> My question is, can I enable NAT traversal on the head office without
>> affecting other tunnels that don't require it?
>>
>> Alternatively, I know that Nokia VPN boxes (Sadly dicontinued) and
>> ASAs can use a management proxy for dynamically addressed sattelite
>> nodes. Can this also be done with Cisco boxes?
>
> My (very limited but perhaps sufficient in this case) understanding
> is that NAT-T is "negotiated" (or maybe discovered is better?) if
> enabled
> and will not affect non NATed links.
>
> I am sure this it works OK since I have some Pixes doing that
> at present.
>
> If you do not know the IP address of the remote site in advance
> you may have to use DMVPN.
>
> Whether the 3725 will run a sufficiently recent IOS
> to have DMVPN I don't know.
>
> Here is a pix (6.4) doing NAT-T (udp encaps) and non NAT-T
>
> sh cry ip sa | inc settings|peer
> current_peer: x.x.x.22:500
> in use settings ={Tunnel, }
> in use settings ={Tunnel, }
> current_peer: x.x.x.74:4500
> in use settings ={Tunnel UDP-Encaps, }
> in use settings ={Tunnel UDP-Encaps, }
> current_peer: x.x.x.24:500
> in use settings ={Tunnel, }
> in use settings ={Tunnel, }

NAT-T is definitely negotiated. A vendor ID string that is sent /
received by the hosts as part of the VPN setup determines if NAT T is
supported by the Hosts. Then I seem to recall a HASH is done on a test
packet which the sender / receiver use as a comparison to see if the
packet has changed in transit. If it has then the hosts know there is a
NAT device in the middle. If not everything carriers on regardless.

So long ago since I read up on this but enabling NAT-T shouldn't break
anything.

Regards

Darren

Similar ThreadsPosted
NAT Traversal. February 21, 2006, 7:16 am
QoS - LLQ on Dialer (ADSL) 3725 February 3, 2006, 7:04 am
Is NM-4E compatible with Cisco 3725 February 8, 2006, 12:47 pm
ISAKMP nat-traversal ? November 28, 2005, 5:54 am
doubts about nat-traversal February 6, 2006, 10:24 am
VPN tunnel with NAT traversal March 30, 2006, 11:51 pm
VPN Nat Traversal Through Watchguards September 20, 2006, 1:55 am
Nat-traversal alternative? March 17, 2007, 6:25 pm
high IP Input CPU on 3725 router January 19, 2006, 12:50 pm
Cisco 3725 can act as a Voip gateway ? November 5, 2007, 5:48 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map