Re: 2 vpn clients on Home LAN



NAT traversal in negotiated for clients that support it. If a client
and the PIX both support NAT traversal (IPSec over UDP), it will be
chosen as the preferred method for the connection. If a client does not
support it, you can still use traditional IPSec.

In other words, using the isakmp nat-traversal command *allows* to PIX
to use IPSec NAT traversal, but doesn't force all connections to use
it. I think!

Keep in mind that the maximum number of traditional IPSec connections
your PIX can support is set by the number of globally routable
addresses available at the outside interface. If you have a pool of say
13 routable addresses assigned at the outside interface, you can
support a max of 13 traditional IPSec sessions. If you enable nat
traversal, you would be able to support many more connections.

.



Relevant Pages

  • Re: 2 vpn clients on Home LAN
    ... and the PIX both support NAT traversal, ... support it, you can still use traditional IPSec. ...
    (comp.dcom.sys.cisco)
  • Re: DNS and IPSEC
    ... We do not support negotiating security with IPsec from client ... We do support it from client-client and client-server however. ... Microsoft Technical Support ...
    (microsoft.public.security)
  • Opinion on Nexland Pro Firewall needed (specs inside)
    ... PPPoE Client ... SNMP Virtual Server for WAN Access ... Microsoft Netmeeting Support ... Compatible with all Standard IPsec Servers ...
    (comp.security.firewalls)
  • Re: Windows 2003 server and CISCO VPN client 4.6
    ... Cisco has supported L2TP+IPsec and PPTP on PIX for some time now. ... PIX and on the client. ... > like a good question to post in a Cisco forum, or check their support ...
    (microsoft.public.windows.server.networking)
  • Re: PIX 501 VPN RAS
    ... So the Pix itself is behind NAT. ... Forget about L2TP over native IPSec (Windows VPN) ... PIX 7.0 does not support L2TP over IPSec. ...
    (comp.dcom.sys.cisco)