Default Domain Name; Ipsec Through Nat; Ipsec Through Nat Udp Port - Cisco VPN 3000 User Manual

Table of Contents

Advertisement

Default Domain Name

Enter the default domain name that the VPN Concentrator passes to the IPSec client, for the client's TCP/
IP stack to append to DNS queries that omit the domain field. This domain name applies only to tunneled
packets. For example, if this entry is xyzcorp.com , a DNS query for mail becomes
mail.xyzcorp.com
syntax.

IPSec through NAT

Check the box to allow the Cisco VPN 3000 Client (IPSec client) to connect to the VPN Concentrator
via UDP through a firewall or router using NAT. The box is not checked by default. See discussion below.

IPSec through NAT UDP Port

Enter the UDP port number to use if you allow IPSec through NAT . Enter a number in the range 4001
through 49151 ; default is 10000 .
About IPSec
IPSec through NAT lets you use the Cisco VPN 3000 Client to connect to the VPN Concentrator via UDP
through NAT
through a firewall or router that is running NAT. This feature is proprietary, it applies only to
remote-access connections, and it requires Mode Configuration. Using this feature may slightly degrade
system performance.
Enabling this feature creates runtime filter rules that forward UDP traffic for the configured port even if
other filter rules on the interface drop UDP traffic. These runtime rules exist only while there is an active
IPsec through NAT session. The system passes inbound traffic to IPSec for decryption and
unencapsulation, and then passes it to the destination. The system passes outbound traffic to IPSec for
encryption and encapsulation, applies a UDP header, and forwards it.
You can configure more than one group with this feature enabled, and each group can use a different port
number. Port numbers must be in the 4001 through 49151 range, which is a subset of the IANA
Registered Ports range.
The Cisco VPN 3000 Client must also be configured to use this feature (it is configured to use it by
default). The VPN Client Connection Status dialog box indicates if the feature is being used. See the
VPN 3000 Client User Guide.
The Administration | Sessions and Monitor | Sessions screens indicate if a session is using IPSec through
NAT, and the Detail screens show the UDP port.
VPN 3000 Concentrator Series User Guide
. Maximum is 255 characters. The Manager checks the domain name for valid
Configuration | User Management | Base Group
12-11

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents