A fix is available
APAR status
Closed as program error.
Error description
IPSec tunnel can be implemented when there is a NAT router between two endpoints using NAT traversal. But communication fails in both directions even though IKE Phase 1 and 2 are completed and IPSec tunnel is active. When NAT Traversal is used, ESP packets are encapsulated in UDP packet with source and destination port 4500. The problem is a server behind NAT router fails to set UDP port to 4500, but these are sent in UDP 0 port. This breaks IPSec communication.
Local fix
Problem summary
IPSec will not work while initiator is behind NAT.As initiator is not receiving the proper VENDOR id from responder.
Problem conclusion
The responder will send proper VENDOR id and initiator and responder both will be able to detect the NAT.
Temporary fix
Comments
APAR Information
APAR number
IV47445
Reported component name
AIX V7.1
Reported component ID
5765H4000
Reported release
710
Status
CLOSED PER
PE
NoPE
HIPER
NoHIPER
Submitted date
2013-08-23
Closed date
2013-08-23
Last modified date
2014-02-14
APAR is sysrouted FROM one or more of the following:
APAR is sysrouted TO one or more of the following:
Fix information
Fixed component name
AIX V7.1
Fixed component ID
5765H4000
Applicable component levels
R710 PSY U854686
UP13/11/22 I 1000
PTF to Fileset Mapping
U854686 bos.net.ipsec.keymgt 7.1.3.0
[{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SSMV87","label":"AIX 6.1 Enterprise Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SSMVAX","label":"AIX Express Edition"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"LOB08","label":"Cognitive Systems"}},{"Business Unit":{"code":"BU054","label":"Systems w\/TPS"},"Product":{"code":"SG11R","label":"AIX 7.1 HIPERS, APARs and Fixes"},"Component":"","ARM Category":[],"Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"710","Edition":"","Line of Business":{"code":"","label":""}}]
Document Information
Modified date:
14 February 2014