Nortel 3050 Command Reference Manual page 300

Vpn gateway
Hide thumbs Also See for 3050:
Table of Contents

Advertisement

300 Command Reference
/cfg/vpn <id> /ipsec/ikeprof <id> /nat IKE Profile NAT
Configuration
[NAT Menu]
natdetect - Set ESP UDP NAT detect
timeout - Set detect timeout
keepalive - Set keepalive timeout
NAT (Network Address Translation) devices on the network path between
the client PC and the VPN Gateway may or may not be IPsec aware.
IPsec aware NAT devices can handle IPsec traffic but if the NAT device
is not IPsec aware, the client PC and the VPN Gateway can negotiate to
encapsulate the IPsec packets within UDP (i.e. the same as NAT traversal
in this document).
The NAT menu is used to configure how NAT device detection and packet
encapsulation should be managed by the VPN Gateway.
Table 109
NAT Menu Options (/cfg/vpn/ipsec/ikeprof/nat)
Command Syntax and Usage
natdetect disabled|auto|ipsec_capable
timeout <value in seconds>
Copyright © 2007 Nortel Networks
.
Lets you make the desired setting for NAT detection.
disabled. Sets the IPsec SA to not encapsulate the IPsec packets
within UDP, even if a NAT device is detected on the way. Used if
the NAT devices are IPsec aware or if there are no NAT devices.
auto. Forces the IPsec SA to encapsulate the IPsec packets within
UDP whenever a NAT device has been detected – even if the NAT
device is IPsec aware.
ipsec_capable. Should be used if both IPsec aware and non IPsec
aware NAT devices exist within the network environment. An IPsec
forwarding subsystem is informed to check whether any traffic is
received on this IPsec SA for the preconfigured interval:
— If traffic is received: This is an indication that the NAT device
on the network path is IPsec aware and no further action is
required.
— If no traffic is received: This indicates that the NAT device is not
forwarding the IPsec traffic and UDP encapsulation is required.
The IPsec forwarding subsystem sends a rekey initiation to IKE
indicating that a new IPsec SA should be established with IPsec
packets encapsulation within UDP.
The default value is disabled.
Nortel VPN Gateway
Command Reference
NN46120-103 01.01 Standard
10 September 2007

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

3070Nvg 3050Nvg 3070Svm 10001000 con?guration guide

Table of Contents