From the course: Cisco CCNP Security SCOR v1.1 (350-701) Cert Prep
Unlock this course with a free trial
Join today to access over 25,300 courses taught by industry experts.
NAT-T for IPsec
From the course: Cisco CCNP Security SCOR v1.1 (350-701) Cert Prep
NAT-T for IPsec
- [Instructor] We need to be able to describe the function of NAT Traversal or NAT-T for this exam. NAT or Network Address Translation is a way that we can convert private IP addresses to publicly routable IP addresses and vice versa. NAT Traversal is a technique for establishing VPN connections across a device that is performing NAT. If we look at this simple diagram, you can see that we have a port address translation happening at the firewall between these two routers with a site to site VPN between the routers. The port address translation that is taking place is a type of NAT where we map multiple private IP addresses to a single public IP, and we assign different ports. So if we have multiple internal IP addresses in the local office, as we see here, these will be translated into a single global IP address with each of those addresses being assigned a unique port from a pool of available ports. The problem is with our VPN security protocols with AH and ESP, those are layer three…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
(Locked)
On-premises threats8m 42s
-
(Locked)
Cloud-based threats7m 42s
-
(Locked)
Software vulnerabilities4m 48s
-
(Locked)
SQL injection6m 47s
-
(Locked)
Buffer overflow5m 13s
-
(Locked)
Cross-site request forgery5m 7s
-
(Locked)
Hashing5m 44s
-
(Locked)
Encryption5m 19s
-
Public key infrastructure (PKI)5m 53s
-
(Locked)
IPsec9m 57s
-
(Locked)
NAT-T for IPsec4m 23s
-
(Locked)
Pre-shared key authentication7m 18s
-
(Locked)
Site-to-site VPN14m 12s
-
(Locked)
Remote access VPN10m 35s
-
(Locked)
sVTI-based VPN9m 20s
-
(Locked)
DMVPN24m 31s
-
FlexVPN5m 20s
-
(Locked)
Cisco DNA Center overview7m 38s
-
(Locked)
Cisco DNA Center and vManage APIs6m 21s
-
(Locked)
Python scripts8m 23s
-
(Locked)
-
-
-
-
-
-