09-25-2017 01:18 AM - edited 09-25-2017 01:23 AM
I have a question about interaction of NAT and IPsec-VPN on vrouter 5600
Regarding Interaction of NAT and IPsec-VPN,
it seems that specification is different between vrouter 5400 and vrouter 5600(5.2R5S3)
because the configuration same as vrouter 5400 didn't work.
In out system,
1. 2 sites are connected through IPsecVPN tunnel ,
2. In both sites users communicate using global IP, so vrouter need to perform both IPsec-VPN and bidirectional NAT function.
3. In vrouter configuration, IPsec tunnel is defined using local/prefix setting (not using VTI).
--In case of using vrouter 5400--
When I start communication from vrouter site to the opposite site or
when I start communication from the opposite site to vrouter site, NAT with IPsec VPN works fine.
--In case of vrouter 5600--
When I start communication from vrouter site to the opposite site,
source NAT works but the packets doesn't go into the IPsec-VPN tunnel.
When I start communication from the opposite site to vrouter site,
the packets flow through the IPsec-VPN tunnel but destination NAT doesn't work
I'm concerned about the specification change from vrouter 5400 regarding interaction of NAT and IPsec-VPN.
Does anyone have information about this ?
Regarding interaction Between NAT, Routing, Firewall, I know the specifation change
( For example,
Thank you .
(athirano1 from Japan)