Re: IPSEC with NAT

From: DN817 <ndheeraj.ccie_at_googlemail.com>
Date: Tue, 3 Aug 2010 08:07:12 +0100

My Service provider opened these UDP ports and now I got EZvpn working.
Thanks, Everyone for your help.

Regards,
DN
On Mon, Aug 2, 2010 at 3:09 AM, Keith Barker <kbarker_at_ine.com> wrote:

> If it works before applying the tunnel protection, it is most likely that
> UDP 500, UDP 4500 or ESP protocol 50 is being blocked or hindered in the
> path. Are there ASAs between the spokes and hubs? If so, you will want to
> enable IPSec passthru on them, as well as permitting the protocols just
> mentioned.
>
> Best wishes,
>
> Keith H. Barker, CCIE #6783
> Instructor
> kbarker_at_ine.com
> Internetwork Expert, Inc.
> http://ine.com
> Toll Free: 877-224-8987
> Outside US: 775-826-4344
>
> On Aug 1, 2010, at 4:21 PM, DN817 wrote:
>
> > Hi,
> >
> > I tried EZVPN & DMVPN, both works when I LAB it up.
> > But both of these doesn't work in LIVE environment. The only difference I
> > have noticed in the LIVE environment is the presence of L2TP session at
> the
> > spoke/client router with the 3G enabler(Teldat) device.
> >
> > In case of DMVPN, the GRE/NHRP everything works fine initially.
> > Then when I enable tunnel protection everything stops working.
> >
> > Do I need do any additional config while running EZVPN or DMVPN when L2TP
> is
> > involved?
> >
> > Thanks,
> > DN

Blogs and organic groups at http://www.ccie.net
Received on Tue Aug 03 2010 - 08:07:12 ART

This archive was generated by hypermail 2.2.0 : Wed Sep 01 2010 - 11:20:52 ART