The log shows "NAT Discovery : Peer IPSec Security Gateway behind a NAT/NAPT Device"

Description

The log shows "NAT Discovery : Peer IPSec Security Gateway behind a NAT/NAPT Device"

Resolution

These messages are sent during initialization of an IKE VPN when NAT Traversal option is enabled. There are some inherent problems while sending IPSec packets through NAT devices. One way to overcome these problems is to encapsulate IPSec packets in UDP. To do this effectively, there is a discovery phase in IKE (Phase1) that tries to determine if either of the IPSec gateways is behind a NAT device. If a NAT device is found, IPSec-over-UDP is proposed during IPSec (Phase 2) negotiation. If there is no NAT device detected, IPSec is used.

Here is the list all possible NAT-Traversal logs during discovery phase.

  • NAT Discovery : Peer IPSec Security Gateway behind a NAT/NAPT Device
  • NAT Discovery : Local IPSec Security Gateway behind a NAT/NAPT Device
  • NAT Discovery : No NAT/NAPT device detected between IPSec Security gateways
  • NAT Discovery : Peer IPSec Security Gateway doesn't support VPN NAT Traversal

Issue ID

SW3815

Related Articles

  • How to configure Link Aggregation
    Read More
  • Web Proxy Forwarding is not Supported to a Server on the LAN
    Read More
  • アプリケーション制御を使用して ICMP(Ping)をブロックする方法
    Read More
not finding your answers?