ipsec+nat (udp encapsulation)

  • Thread starter Thread starter Guest
  • Start date Start date
hello

does win2000 (and win2003) support udp encapsulation?

thanx
alex

Don't have the answer but you may find a useful reference here
www.labmice.net also the below KB article may have something for you.

Microsoft Knowledge Base Article - 301284
Quote:
NAT and IPSec Are Incompatible
If there is any Network Address Translation (NAT) between the two endpoints,
IPSec does not work. IPSec embeds endpoint addresses as part of the payload.
IPSec also uses source addresses when it computes packet checksums before
depositing the packets on the wire. NAT can change the source address of
outbound packets, and the destination uses the address in the header when it
computes its own checksums. The original source-computed checksums, carried
in the packets, do not match the destination-computed checksums, and the
destination can drop the packets. You cannot use IPSec with any type of NAT
device.
Endquote.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

Re: Open a port for a VPN Router 1
IPsec and UDP (SNMP) 1
IPsec and DCs 5
IPSec and TCP/IP filtering 3
IpSec filtering 4
class module and encapsulation 2
IPSec on webserver 3
L2TP IPSec error 789 & 792 0

Back
Top