Jul 04

Here is a short summary of ports thatn need to be open for DMVPN, GETVPN and IPSec that has a firewall inbetween

1. DMVPN (best enterprise VPN so far)
ESP
ISAKMP udp 500
NON-ISAKMP udp 4500 (if you have NAT-T)

2. GETVPN (encryption for your MPLS traffic)

    udp 848

For Getvpn if you are using multicast key redisitribution you also need to open 848 to 239.0.1.2

3. IPSEC (Ezvpn and old stuff :-) )

ESP
ISAKMP udp 500
NON-ISAKMP udp 4500 (if you have NAT-T)
GRE (if you are using it)

Please submit a comment as this is a Draft only

One Response to “DMVPN, GETVPN and IPSec firewall ports to be open”

Leave a Reply

preload preload preload