Support Support Downloads Knowledge Base Case Manager My Juniper Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

Traffic not getting through NAT traversal VPN - LAN to LAN



Article ID: KB6130 KB Last Updated: 28 Jun 2010Version: 4.0

  • NetScreen firewall without NAT has static assigned IP address
  • LAN to LAN VPN
  • One NetScreen behind NAT device, other has no NAT device in front of it
Symptoms & Errors:
  • Pings not getting through NAT traversal VPN
  • VPN not working with NAT traversal

NetScreen behind NAT device:
Specify a local id when configuring the IKE Gateway
NetScreen without NAT device:
Specify Dynamic Gateway, peer id= local id used when specifying IKE gateway on the NetScreen behind NAT device
Local ID: NSA Peer ID: NSA
Initiate traffic from the NetScreen behind the NAT device (NS A), and the NetScreens will begin its negotiation of Phase 1 and Phase 2 IKE.  It will generally take longer for the IKE negotiation phase to complete, as it requires more messages to verify the gateway behind the NAT device.

Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search