Support
Joined: 09 Oct 2002 Posts: 175 Location: Lausanne, Switzerland
|
Posted: Tue Jan 14, 03 11:35 Post subject: Can ESP packets to traverse NAT from the LAN to the WAN? |
|
|
When NAT is activated the answer is no. The ESP packets are changed and hence the authentication portion of the IPSec protocol will fail. The MultiCom Firewall with NAT enabled must be an endpoint for the encrypted packets. If you do not enable NAT then the ESP packets will be routed without a problem based on their IP header.
When NAT is not activated, the ESP packets can be routed as though it was passing through any other router on the Internet. |
|