How can I disable/enable NAT traversal in VPN settings? | SonicWall (2024)

How can I disable/enable NAT traversal in VPN settings? | SonicWall (1) 09/29/2023 How can I disable/enable NAT traversal in VPN settings? | SonicWall (2) 52 People found this article helpfulHow can I disable/enable NAT traversal in VPN settings? | SonicWall (3) 470,921 Views

Description

How can I disable/enable NAT traversal in VPN settings? | SonicWall (4) NOTE: This article describes about NAT traversal taking tunnel mode and ESP protocol as an example, NAT traversal also supported in AH protocol and in transport mode.

What is NAT-T or NAT traversal in IPSEC VPN?.

Traditionally, IPsec does not work when traversing across a device doing NAT/PAT(Network Address Translation and Port Address Translation), meaning if either one of the devices or both the devices terminating IPSEC is behind a NAT device, IPSEC will not work. To overcome this problem, NAT-T or NAT Traversal was developed.

NAT-T is an IKE phase 1 algorithm that is used when trying to establish a IPSEC VPN between two gateway devices where there is a NAT device in front of one of the gateway devices or both the gateway devices.

What is the Purpose of using NAT-T feature?.

In IPSEC, all critical information along with UDP/TCP header is encapsulated within ESP or AH header, ESP and AH itself is an protocol like TCP or UDP and carries no port information.If a NAT device is in between two IPSEC gateways anddoingmany to one NAT, it needs to do PAT(Port address translation) as well to maintain a consistent and proper session table. If a packet is encapsulated by ESP or AH header, PAT/NAT device will not have port information to translate source port and result is IPSEC traffic will not pass through the PAT/NAT device.When we use NAT-T Feature, IPSEC traffic is encapsulated using UDP header with source and destination port number as 4500 and provides port information for the NATdevice to do Port Address Translation. How does NAT-T or NAT traversal works: In IKE main mode, first two messages detect whether NAT-T feature is supported on the IPSEC gateways and three and four messages detects whether there is NAT device between IPSEC gateways. If IPSEC gateways support NAT-T feature, both devices send NAT-D(NAT Discovery) payload, payload is the hash of source and destination IP and Source and destination port, receiving device will recalculate the hash, if hash matches there is no NAT device in between, if hash doesn't match there is a NAT device in between. If the IPSEC gateways detects an existence of NAT device, from message five and six of Phase 1, all IPSECpackets are encapsulated using UDP header with source and destination as port 4500(including quick mode messages and user data).

Packet Format of ESP in tunnel Mode without NAT-T
How can I disable/enable NAT traversal in VPN settings? | SonicWall (5)

Packet Format of ESP in tunnel Mode withNAT-T:
How can I disable/enable NAT traversal in VPN settings? | SonicWall (6)

How can I disable/enable NAT traversal in VPN settings? | SonicWall (7) NOTE: To perform NAT traversal process both the IPSEC gateway devices should support NAT-T even though a particular device is not behind NAT device.

Resolution

Resolution for SonicOS 7.X

This release includes significantuser interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.

  1. Navigate to Network | IPSec VPN | Advanced | Enable NAT traversal.
  2. By default in all SonicOS, NAT traversal will be enabled.

How can I disable/enable NAT traversal in VPN settings? | SonicWall (8)

How can I disable/enable NAT traversal in VPN settings? | SonicWall (9) NOTE: NAT traversal feature in SonicWall is a global settings, changing this settings will affect all Global VPN and site to site VPN policies, also note that enabling this feature will not have impact on normal VPN working even though IPSEC gateways are not behind NAT device but disabling this feature will have impact the VPN policies where IPSEC gateway is behind NAT device.

Resolution for SonicOS 6.5

This release includes significantuser interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.

  1. Navigate to Manage |Connectivity |VPN | Advance settings| Enable/Disable NATtraversal.
  2. By default in all SonicOS, NATtraversal will be enabled.
    How can I disable/enable NAT traversal in VPN settings? | SonicWall (10)

    How can I disable/enable NAT traversal in VPN settings? | SonicWall (11) NOTE: NAT traversal feature in SonicWall is a global settings, changing this settings will affect all Global VPN and site to site VPN policies, also note that enabling this feature will not have impact on normal VPN working even though IPSEC gateways are not behind NAT device but disabling this feature will have impact the VPN policies where IPSEC gateway is behind NAT device.

Resolution for SonicOS 6.2 and Below

The below resolution is for customers using SonicOS 6.2 and earlier firmware. For firewalls that are generation 6 and newer we suggest to upgrade to the latest general release of SonicOS 6.5 firmware.

  1. Navigate to VPN settings|Advance settings| Enable/Disable NATtraversal.
  2. By default in all SonicOS, NATtraversal will be enabled.
    How can I disable/enable NAT traversal in VPN settings? | SonicWall (12)

    How can I disable/enable NAT traversal in VPN settings? | SonicWall (13) NOTE: NAT traversal feature in SonicWall is a global settings, changing this settings will affect all Global VPN and site to site VPN policies, also note that enabling this feature will not have impact on normal VPN working even though IPSEC gateways are not behind NAT device but disabling this feature will have impact the VPN policies where IPSEC gateway is behind NAT device.

Related Articles

  • NSv upgrade from 7.0.1 to 7.1.X
  • Netextender failing to connect with error "Initializing engine…failed"
  • High Availability setup not working - Error Contacting Peer HA Firewall

Categories

  • Firewalls > TZ Series > VPN
  • Firewalls > NSa Series > VPN
  • Firewalls > NSv Series > VPN

Not Finding Your Answers?

ASK THE COMMUNITY

Was This Article Helpful?

How can I disable/enable NAT traversal in VPN settings? | SonicWall (14)YESHow can I disable/enable NAT traversal in VPN settings? | SonicWall (15)NO

How can I disable/enable NAT traversal in VPN settings? | SonicWall (2024)
Top Articles
Putting A House In A Trust - Should You Do It? | Versus Law Solicitors
Maritime Forecast to 2050
Koopa Wrapper 1 Point 0
Uti Hvacr
Ets Lake Fork Fishing Report
Missed Connections Inland Empire
Craigslist Campers Greenville Sc
25X11X10 Atv Tires Tractor Supply
Health Benefits of Guava
Driving Directions To Fedex
What to Serve with Lasagna (80+ side dishes and wine pairings)
Evil Dead Rise Showtimes Near Massena Movieplex
Naturalization Ceremonies Can I Pick Up Citizenship Certificate Before Ceremony
Farmers Branch Isd Calendar
Locate Td Bank Near Me
Camstreams Download
Myql Loan Login
No Strings Attached 123Movies
6001 Canadian Ct Orlando Fl
Peraton Sso
The ULTIMATE 2023 Sedona Vortex Guide
Cinebarre Drink Menu
Blackwolf Run Pro Shop
Who called you from +19192464227 (9192464227): 5 reviews
Mikayla Campinos Laek: The Rising Star Of Social Media
Nurse Logic 2.0 Testing And Remediation Advanced Test
Quadcitiesdaily
Weve Got You Surrounded Meme
Best Boston Pizza Places
Hannaford Weekly Flyer Manchester Nh
Emuaid Max First Aid Ointment 2 Ounce Fake Review Analysis
Parent Management Training (PMT) Worksheet | HappierTHERAPY
Life Insurance Policies | New York Life
Memberweb Bw
Plato's Closet Mansfield Ohio
Soulstone Survivors Igg
Ksu Sturgis Library
Ticket To Paradise Showtimes Near Marshall 6 Theatre
Trivago Myrtle Beach Hotels
Stanley Steemer Johnson City Tn
Craigslist Pa Altoona
M Life Insider
Best Restaurants Minocqua
How to Quickly Detect GI Stasis in Rabbits (and what to do about it) | The Bunny Lady
Pekin Soccer Tournament
Parent Portal Pat Med
Autozone Battery Hold Down
Dancing Bear - House Party! ID ? Brunette in hardcore action
300 Fort Monroe Industrial Parkway Monroeville Oh
Strange World Showtimes Near Century Federal Way
Skybird_06
How to Choose Where to Study Abroad
Latest Posts
Article information

Author: Melvina Ondricka

Last Updated:

Views: 5992

Rating: 4.8 / 5 (48 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Melvina Ondricka

Birthday: 2000-12-23

Address: Suite 382 139 Shaniqua Locks, Paulaborough, UT 90498

Phone: +636383657021

Job: Dynamic Government Specialist

Hobby: Kite flying, Watching movies, Knitting, Model building, Reading, Wood carving, Paintball

Introduction: My name is Melvina Ondricka, I am a helpful, fancy, friendly, innocent, outstanding, courageous, thoughtful person who loves writing and wants to share my knowledge and understanding with you.