- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
NAT Unfriendly
Hello,
I am receiving the NAT unfriendly alert on my VPN status page. Does this alert can cause the VPN not going up?
Regards
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes it could.
It means there is something doing NAT in front of the MX. You could try upgrading the firmware of whatever that device is to resolve the problem. There is also a troubleshooting guide here:
You could also manually forward a UDP port on that upstream router to the MX and configure the MX to use manual NAT traversal.
https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Settings#NAT_Traversal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes it could.
It means there is something doing NAT in front of the MX. You could try upgrading the firmware of whatever that device is to resolve the problem. There is also a troubleshooting guide here:
You could also manually forward a UDP port on that upstream router to the MX and configure the MX to use manual NAT traversal.
https://documentation.meraki.com/MX/Site-to-site_VPN/Site-to-site_VPN_Settings#NAT_Traversal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This guide includes a screenshot:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@PhilipDAth Why is NAT unfriendly a problem? If outside (NATed) source IP or port are inconsistent, the inside IP and src port are not so the data gets always forwarded to the same host.
What am I missing?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Because the NAT needs to allow return packets from any IP address to work. Then every other MX can establish an AutoVPN link directly to the MX.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@PhilipDAth Can you please explain in more detail?
Are you saying that in one moment in NAT translation table there will be MX private IP address mapped to one public IP address and/or port, and in other moment they will be different. So, the returned traffic will have IP/port mismatch and the data would not get forwarded correctly?
How often MX registers its IP and port to the VPN registrator?
![](/skins/images/7B34708A1980CF5E136B7318F0CE9B4A/responsive_peak/images/icon_anonymous_message.png)