< Home

firewall esp nat enable

Function

The firewall esp nat enable command enables the ESP NAT function.

The undo firewall esp nat enable command disables the ESP NAT function.

Format

firewall esp nat enable

undo firewall esp nat enable

Parameters

None

Views

System view

Default Level

2: Configuration level

Usage Guidelines

In a scenario where the FW serves as a NAT device in the middle of an IPSec tunnel, if the devices at the two ends of the tunnel do not support the NAT traversal function, you must configure the ESP NAT function on the FW so that ESP packets can properly pass.

By default, the ESP NAT function is disabled.

In the ESP NAT configuration, ensure that devices at both ends of the IPSec tunnel have the NAT traversal function disabled.

Example

# Enable the ESP NAT function.

<sysname> system-view
[sysname] firewall esp nat enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >