Passthrough ipsec esp packets

Hi guys

We have a situation where competitor cell modems will not properly pass ipsec esp packets unless they have been udp encapsulated.

Turning udp encapsulation in Windows requires a regedit and reboot which is do-able, but for Android and Ipads, I have no idea how to do a work around.

I want to suggest to the customer that they not use a cell modem in front of their vpn appliance but out of curiosity, does Teltonika have any kind of magic that will properly bridge the cell interface to the lan interface? Or forward ESP packets? Or something that will allow this remote location to keep using cell?

Thanks all.

Hello,

Teltonika devices do have a Force encapsulation option available in the IPsec advanced settings tab. This setting forces UDP encapsulation for ESP packets even if no NAT situation is detected, which can help in scenarios where upstream modems or networks mishandle native ESP traffic.

Additionally, by default, there’s a traffic rule created to accept IPsec ESP traffic forwarding it to the LAN:
image

Hope this clarifies the capabilities and helps here.

Best regards,

Will ESP forwarding work in 1to1 passthrough mode?

Hello,

If the modem has a public IP address and is in passthrough mode, then ESP packet forwarding should work.

Best regards,