Loading...
Loading...
IPsecALG resources will remain in use even after IPsec clients switch to NAT-T and do not send ESP packets. ESP connections will be setup, but not used. They will remain until the 'idle-timeout' specified in the IPsecALG profile has been reached. Translation endpoints will be unavailable until the 'idle-timeout' specified in the IPsecALG profile has been reached.
IPsec clients that are not using NAT-T will not be able to establish connections if the translation addresses are in use to the same server. This condition will clear after the IPsecALG profile 'idle-timeout' expires.
An IPsecALG profile is attached to a UDP virtual to handle IKE traffic with LSN or AFM FW-NAT enabled. IPsec clients detect the NAT and transition to NAT-T instead of sending ESP packets.
None
None
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.