The log shows "NAT Discovery : Peer IPSec Security Gateway behind a NAT/NAPT Device"

Description

The log shows "NAT Discovery : Peer IPSec Security Gateway behind a NAT/NAPT Device"

Resolution

These messages are sent during initialization of an IKE VPN when NAT Traversal option is enabled. There are some inherent problems while sending IPSec packets through NAT devices. One way to overcome these problems is to encapsulate IPSec packets in UDP. To do this effectively, there is a discovery phase in IKE (Phase1) that tries to determine if either of the IPSec gateways is behind a NAT device. If a NAT device is found, IPSec-over-UDP is proposed during IPSec (Phase 2) negotiation. If there is no NAT device detected, IPSec is used.

Here is the list all possible NAT-Traversal logs during discovery phase.

  • NAT Discovery : Peer IPSec Security Gateway behind a NAT/NAPT Device
  • NAT Discovery : Local IPSec Security Gateway behind a NAT/NAPT Device
  • NAT Discovery : No NAT/NAPT device detected between IPSec Security gateways
  • NAT Discovery : Peer IPSec Security Gateway doesn't support VPN NAT Traversal

Issue ID

SW3815

Related Articles

  • SSH password authentication fails after OpenSSH upgrade
    Read More
  • Where can I download SonicWall stencils?
    Read More
  • Configuring High Availability Monitoring settings
    Read More
not finding your answers?