NAT-T
Adds layer of UDP encapsulation to protect IPSec from being discarded translation
Enables connecting to resources behind NAT
Ensure IPSec connections remain open while traffic is going through NAT
NAT-T if not used, needs to be disabled, otherwise tunnel won't establish
AWS Defaults to using NAT-T technique
Uses ISAKMP to negotiate security parameter
Used in main-mode and quick-mode of IPSec
Uses port 4500 with ipsec unaware NAT
Last updated