Quantcast
Channel: All SRX Services Gateway posts
Viewing all articles
Browse latest Browse all 17645

Re: Why is the SRX using NAT-T for the IPSEC?

$
0
0

Hi

 

The NAT rule that you created,

 

set security nat source rule-set SNAT_use_interface from routing-instance default
set security nat source rule-set SNAT_use_interface to zone Untrust

 

is very general, I suspect it pertains also to the locally generated IKE traffic. Then it makes SRX to change (due to PAT) the default IKE 500 port of the outgoing IKE session. (Not sure if IP changes as well in your setup.) The other device will ignore such packets if NAT-T is not enabled on it.

 

You can check "show security flow session destination-port 500" command at the time of IKE re-negotiation to see what really happens to the port.

 


Viewing all articles
Browse latest Browse all 17645

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>