HPE GreenLake Administration
- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- HP-UX IPSec NAT-T support
Operating System - HP-UX
1833584
Members
3532
Online
110061
Solutions
Forums
Categories
Company
Local Language
back
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
back
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Blogs
Information
Community
Resources
Community Language
Language
Forums
Blogs
Topic Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2008 10:06 AM
03-28-2008 10:06 AM
HP-UX IPSec NAT-T support
Hi All,
I just tested the interconnectivity of IPSec between Windows XP and HP-UX 11.23. It works perfectly without NAT. After I put a NAT device in front of my XP (client), the tunnel cannot be established. I sniffed the traffic and found the XP sent a Vendor ID for NAT-T but the response from HP-UX did not contain the same VID. I checked the HP-UX IPSec document for IPSec spec, and did not find any support information on NAT-T. Has anyone got this problem before?
I just tested the interconnectivity of IPSec between Windows XP and HP-UX 11.23. It works perfectly without NAT. After I put a NAT device in front of my XP (client), the tunnel cannot be established. I sniffed the traffic and found the XP sent a Vendor ID for NAT-T but the response from HP-UX did not contain the same VID. I checked the HP-UX IPSec document for IPSec spec, and did not find any support information on NAT-T. Has anyone got this problem before?
2 REPLIES 2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2008 11:29 AM
03-28-2008 11:29 AM
Re: HP-UX IPSec NAT-T support
If i understood your problem, to use NAT-T try this:
1. Enable IPSec over NAT-T globally on the security appliance.
2. Select the "before-fragmentation" option for the IPSec fragmentation policy. This option lets traffic travel across NAT devices that do not support IP fragmentation. It does not impede the operation of NAT devices that do support IP fragmentation.
3. Set a keepalive value, which can be from 10 to 3600 seconds. The default is 20 seconds.
To enable NAT-T globally on the security appliance, enter the following command:
isakmp nat-traversal natkeepalive
1. Enable IPSec over NAT-T globally on the security appliance.
2. Select the "before-fragmentation" option for the IPSec fragmentation policy. This option lets traffic travel across NAT devices that do not support IP fragmentation. It does not impede the operation of NAT devices that do support IP fragmentation.
3. Set a keepalive value, which can be from 10 to 3600 seconds. The default is 20 seconds.
To enable NAT-T globally on the security appliance, enter the following command:
isakmp nat-traversal natkeepalive
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-28-2008 12:12 PM
03-28-2008 12:12 PM
Re: HP-UX IPSec NAT-T support
Hi Alcino Silva,
Thank you for your answer. What "appliance" did you mean?
My question is if HP-UX's IPSec stack supports NAT-T so that a windows XP client can connect to the HP-UX server with host-to-host IPsec tunnel through any NAT device. Looks like Windows XP supports NAT-T. But I am not sure if HP-UX supports it.
Thanks...
Thank you for your answer. What "appliance" did you mean?
My question is if HP-UX's IPSec stack supports NAT-T so that a windows XP client can connect to the HP-UX server with host-to-host IPsec tunnel through any NAT device. Looks like Windows XP supports NAT-T. But I am not sure if HP-UX supports it.
Thanks...
The opinions expressed above are the personal opinions of the authors, not of Hewlett Packard Enterprise. By using this site, you accept the Terms of Use and Rules of Participation.
Company
Events and news
Customer resources
© Copyright 2025 Hewlett Packard Enterprise Development LP