AM <Alex@AM.AM> writes:
> Does NAT-T needed when remote vpnpoint is behind a device doing NAT or
> it is needed only if the device is not IPsec passthrough?
If you only have one user behind the NAT box using IPsec and the NAT
box supports IPsec passthrough then you don't need NAT-T, though you
may prefer to use it depending on the quality of the IPsec passthrough
support in the NAT box.
If you have multiple users behind the same NAT box all wanting to use
IPsec then most (all?) NAT IPsec passthrough implementations will
result in one or more of the IPsec connections failing unless the
client turns on NAT-T.
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.