Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

IKEv2 with NAT-T and dynamic endpoint VPN

More Information:

IKEv2 with NAT-T and dynamic endpoint VPN

Both IKEv2 initiators and responders in a route-based VPN can be behind NAT devices. The IKEv2 NAT-T feature supports IPsec traffic that crosses NAT devices. Static NAT and dynamic NAT are supported. In static NAT, there is a one-to-one relationship between the private and the public addresses. In dynamic NAT, there is a many-to-one or many-to-many relationship between the private and public addresses. Dynamic endpoint (DEP) VPN is a Junos OS feature that covers IKEv2 initiator and responder perspectives. From the initiator's perspective, DEP VPN covers the situation where the IKE external interface address is not fixed and is therefore not known by the responder. This situation can occur when the peer's address is dynamically assigned by an ISP or when the peer's connection crosses a NAT device that allocates addresses from a dynamic address pool. From the responder's perspective, DEP VPN describes either a finite number of VPNs that are created for a number of VPN peers in a many-to-many scenario or a shared VPN in a many-to-one scenario.
Product / Application Software Introduced Release
vSRX Junos OS 12.1X46-D10
SRX300 Junos OS 15.1X49-D35
SRX320 Junos OS 15.1X49-D35
SRX340 Junos OS 15.1X49-D35
SRX345 Junos OS 15.1X49-D35
SRX380 Junos OS 20.1R1
SRX550 Junos OS 12.1X46-D10
SRX550 HM Junos OS 15.1X49-D30
SRX5400 Junos OS 12.1X46-D10
SRX5600 Junos OS 12.1X46-D10
SRX5800 Junos OS 12.1X46-D10