Chapter 8 Configuring IPSec mobility and persistent mode
151
Nortel VPN Router Configuration — Basic Features
Roaming from behind NAT to no NAT
In
Figure 31
before roaming a client was connected via AP1 and NAT box and had
IP1 IP address. After roaming, the client is connected via AP2 without NAT, UDP
encapsulation will be used.
Figure 31
Roaming from behind NAT to no NAT
Roaming from no NAT to behind NAT
Before roaming, the client had access via AP2 and after roaming via AP1 and
NAT box, a situation that’s the reverse of the one in
Figure 31
. In this case, the
IPSec connection will be dropped as NAT detection is made in IKE phase 1 and
NAT traversal is negotiated in quick mode; therefore with the tunnel already
negotiated and established, the change cannot take place unless re-negotiation
occurs.
Similar problems may arise when roaming from behind IPSec aware NAT devices
to behind other NAT devices. To avoid any NAT related problems, the “Always
UDP Encap” option under the IPSec group configuration always forces UDP
wrapping on IPSec user tunnels even if NAT was not detected during connection
establishment.
Summary of Contents for Contivity 1050
Page 10: ...10 Contents NN46110 500 ...
Page 14: ...14 Tables NN46110 500 ...
Page 22: ...22 Preface NN46110 500 ...
Page 58: ...58 Chapter 2 Getting started NN46110 500 ...
Page 74: ...74 Chapter 3 Setting up the Nortel VPN Router 1010 1050 and 1100 NN46110 500 ...
Page 90: ...90 Chapter 4 Configuring user tunnels NN46110 500 ...
Page 118: ...118 Chapter 5 Configuring the system NN46110 500 ...
Page 162: ...162 Chapter 8 Configuring IPSec mobility and persistent mode NN46110 500 ...
Page 164: ...164 Branch office quick start template NN46110 500 ...
Page 178: ...178 Index NN46110 500 W Web browser interface 50 Web interface options 53 Welcome display 56 ...