Port ESP IP protocol 50 test failed

FishMan
Comes here often

Port ESP IP protocol 50 test failed

i have a juniper VPN need to install, a testing tool to test for

 

1. Port UDP/IKE 500: OK

2. Port UDP/NAT-T 4500: OK

3. Port ESP IP protocol 50: FAILED

 

can someone help why port ESP IP protocol 50: FAILED and how to fixed

 

Regards

7 Replies 7
KarstenI
Kind of a big deal
Kind of a big deal

Is your VPN gateway behind a NAT or PAT gateway? Then you don't need IP/50. And with PAT it typically can't be forwarded as there are no ports to translate.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
FishMan
Comes here often

Thanks Karstenl

 

currently i use port forwarding

 

but they need to make sure that all testing ok with no failed, how could I get this done

 

Regards

KarstenI
Kind of a big deal
Kind of a big deal

Then you probably have to configure a 1:1 NAT with a free IP and forward all traffic. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
FishMan
Comes here often

Hi Karsrenl

 

can you guide how to do 1:1NAT

 

Regards

KarstenI
Kind of a big deal
Kind of a big deal

it's well described in the documentation:

https://documentation.meraki.com/MX/NAT_and_Port_Forwarding/Port_Forwarding_and_NAT_Rules_on_the_MX

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
FishMan
Comes here often

i am looking forward on how to allow /16 range to one private ip address using 1:1NAT

 

Regards

KarstenI
Kind of a big deal
Kind of a big deal

Where does this /16 come from? If you have one VPN gateway you need one IP address.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.