Application Layer Gateway for IPSec Protocol
How IPSec ALG Works
IPSec ALG Timeouts
-
ESP Gate Timeout. Maximum time that the NetScaler appliance blocks an IPSec ALG gate for a particular client on a specific NAT IP address for a given server if no two-way ESP traffic is exchanged between the client and the server.
-
IKE Session Timeout. Maximum time that the NetScaler appliance keeps the IKE session information before removing it if there is no IKE traffic for that session.
-
ESP Session Timeout. Maximum time that NetScaler appliance keeps the ESP session information before removing it if there is no ESP traffic for that session.
Points to Consider before Configuring IPSec ALG
-
You must understand the different components of IPSec protocol.
-
IPSec ALG is not supported for DS-Lite and Large scale NAT64 configurations.
-
IPSec ALG is not supported for hairpin LSN flow.
-
IPSec ALG does not work with RNAT configurations.
-
IPSec ALG is not supported in NetScaler clusters.
Configuration Steps
-
Create an LSN application profile and bind it to the LSN configuration. Set the following parameters while configuring an application profile:
-
Protocol=UDP
-
IP Pooling = PAIRED
-
Port=500
-
-
Create an IPSec ALG profile. An IPSec profile includes various IPSec timeouts, such as IKE session timeout, ESP session timeout, and ESP gate timeout. You bind an IPSec ALG profile to an LSN group. An IPSec ALG profile has the following default settings:
-
IKE session timeout = 60 minutes
-
ESP session timeout = 60 minutes
-
ESP gate timeout = 30 seconds
-
-
Bind the IPSec ALG profile to the LSN configuration. IPSec ALG is enabled for an LSN configuration when you bind an IPSec ALG profile to the LSN configuration. Bind the IPSec ALG profile to the LSN configuration by setting the IPSec ALG profile parameter to the name of the created profile in the LSN group. An IPSec ALG profile can be bound to multiple LSN groups, but an LSN group can have only one IPSec ALG profile.
To create an LSN application profile by using the command line interface
add lsn appsprofile <appsprofilename> UDP -ippooling PAIRED
show lsn appsprofile
To bind destination port to the LSN application profile by using the command line interface
bind lsn appsprofile <appsprofilename> <lsnport>
show lsn appsprofile
To bind an LSN application profile to an LSN group by using the command line interface
bind lsn group <groupname> -appsprofilename <string>
show lsn group
To create an IPSec ALG profile by using the CLI
add ipsecalg profile <name> [-ikeSessionTimeout <positive_integer>] [-espSessionTimeout <positive_integer>] [-espGateTimeout <positive_integer>] [-connfailover ( ENABLED | DISABLED)
show ipsecalg profile <name>
To bind an IPSec ALG profile to an LSN configuration by using the CLI
bind lsn group <groupname> -poolname <string> - ipsecAlgProfile <string>
show lsn group <name>
To create an LSN application profile and bind it to an LSN configuration by using the GUI
To create an IPSec ALG profile by using the GUI**
To bind an IPSec ALG profile to an LSN configuration by using the GUI**
-
Navigate to System > Large Scale NAT > LSN Group, open the LSN group.
-
In Advanced Settings, click + IPSEC ALG Profile to bind the created IPSec ALG profile to the LSN group.
Sample Configuration
add lsn client LSN-CLIENT-1
Done
bind lsn client LSN-CLIENT-1 -network 192.0.2.0 -netmask 255.255.255.0
Done
add lsn pool LSN-POOL-1
Done
bind lsn pool LSN-POOL-1 203.0.113.3-203.0.113.9
Done
add lsn appsprofile LSN-APPSPROFILE-1 UDP -ippooling PAIRED
Done
bind lsn appsprofile LSN-APPSPROFILE-1 500
Done
add ipsecalg profile IPSECALGPROFILE-1 -ikeSessionTimeout 45 –espSessionTimeout 40 –espGateTimeout 20 -connfailover ENABLED
Done
bind lsn group LSN-GROUP-1 -appsprofilename LSN-APPSPROFILE-1
Done
bind lsn group LSN-GROUP-1 -poolname LSN-POOL-1
Done
bind lsn group LSN-GROUP-1 - ipsecAlgProfile IPSECALGPROFILE-1
Done