VMware NSX

  • 1.  About IPsec VPN Phase 1 Negotiation mode

    Posted Aug 17, 2023 03:15 AM

    Hi there. This is my first topic here.

    I'm using NSX 4.1.0.2 to creative IPsec VPN with other branches, But I found it did not support aggressive mode, I googled some pages, Only few old docs reference it's only support "Main Mode".

    VMware NSX-V docs(2019/5),It shows:"NSX Data Center for vSphere supports only the standard negotiation mode (main mode)":
    https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSphere/6.4/com.vmware.nsx.troubleshooting.doc/GUID-E995869C-82EE-462C-A4CB-35751ACAED6D.html

    IPsec VPN Settings Reference(2022/6),It shows:"Main mode (Disable aggressive mode)"
    https://docs.vmware.com/en/VMware-Cloud-on-AWS-GovCloud-(US)/services/vmc-govcloud-networking-security/GUID-557F1F18-22A0-47BB-989E-8B1E8275AE02.html

    My questions is: Why did NSX IPsec VPN did not support Agressive Mode? Is there any possible in future to support this mode?

    Thanks a lot!

     



  • 2.  RE: About IPsec VPN Phase 1 Negotiation mode

    Posted Aug 17, 2023 07:55 AM

    I am not a friend of the aggressive mode. The main mode also protects the identity of the endpoints by encrypting their information, while the aggressive mode sends it in plain text. Maybe that's why VMware doesn't support this mode. In general, I don't know of any plans to change it.



  • 3.  RE: About IPsec VPN Phase 1 Negotiation mode

    Posted Aug 18, 2023 01:03 AM

    Thanks dude.

    Some of our customer set the device with internal ip(172.16.x.x,10.x.x.x), and use aggressive mode IKE with NAT traversal.

    They don't like to change, so I am trying to figure it out. But NSX did not support aggressive mode.

    Or does NSX IPsec VPN can process NAT traversal in main mode?



  • 4.  RE: About IPsec VPN Phase 1 Negotiation mode

    Posted Aug 18, 2023 07:01 AM

    I haven't done much with VPN and NSX in the past, but if I remember correctly, NSX can't do NAT-T. In this case you need a NAT deivce in front of your edge node. I'm not 100% sure though, maybe someone else can comment.



  • 5.  RE: About IPsec VPN Phase 1 Negotiation mode

    Posted Sep 01, 2023 03:09 AM

    I was noticed there was a "NAT-T"  shows in cli mode, when I input "get ipsecvpn ipsecsa" command on edge, but not sure where is it in web UI.

     



  • 6.  RE: About IPsec VPN Phase 1 Negotiation mode
    Best Answer

    Posted Sep 01, 2023 09:15 AM

    Finally, I found the "NAT-T" was an automatic option, When Peer ID was an internal IP and Peer IP was a public IP, NSX will be automaticlly set NAT-T option on "TRUE".

    bustmovels_1-1699586957405.png