VPN NAT Traversal when both USG are behind CGNAT with unpredictable source port

PeterUK
PeterUK Posts: 3,160  Guru Member
Community MVP 2500 Comments Sixth Anniversary 100 Answers
edited July 2 in Security Ideas

I'm not sure this will happen due to how it can only be done where by both ends are behind CGNAT with no incoming allowed and unpredictable source port mapping but here is one hell of a way to do it! Not 100% sure it would work.

Here how port 500 Traversal would go then the same for 4500

1 votes

Active · Last Updated

Comments

  • PeterUK
    PeterUK Posts: 3,160  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    So after going through how it work it don't then relooked to how might of worked but it ended up being impossible so one end source port must be true on one side

  • PeterUK
    PeterUK Posts: 3,160  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers

    So this is the best that can be done where both end are CGNAT no incoming allowed and one side has source port that are true.