which port should (or would) be open if VPN NAT-T was enabled

Posted by: Pdfprep Category: 210-260 Tags: , ,

which port should (or would) be open if VPN NAT-T was enabled
A . port 500
B . port 500 outside interface
C . port 4500 outside interface
D . port 4500 ipsec

Answer: D

Explanation:

NAT traversal: The encapsulation of IKE and ESP in UDP port 4500 enables these protocols to pass through a device or firewall performing NAT.

Source: https://en.wikipedia.org/wiki/Internet_Key_Exchange Also a good reference

Source: https://supportforums.cisco.com/document/64281/how-does-nat-t-work-ipsec

Leave a Reply

Your email address will not be published.