Loading...
Loading...
When NAT-T is ON in the IKE-peer configuration on the BIG-IP system, but there is no NATing in the network, IKE negotiation succeeds and brings up SAs correctly. But IPsec (ESP) packets will not pass because of a mismatch in the expected port number (4500 rather than 500) while receiving ESP packets.
IPsec packets are dropped and traffic loss.
NAT_T is ON on the BIG-IP system and there is no NATing in the network.
Do not configure NAT on the BIG-IP system if there is no NATing in the network.
NAT-T is configured but there is no NAT in the network, IPsec now works as expected.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.