[ASK] IPSec Sangfor NGAF ↔ Cisco 881 Behind NAT (Dynamic/Dial-up Scenario)

Fajri Rohmana Lv1Posted Dec-06-2025 19:44

Hi everyone,

I’m working on an IPSec Site-to-Site VPN between Sangfor NGAF M5400 (FW 8.0.39) and a Cisco 881 router, but the Cisco side is behind a NAT gateway and has no direct public IP. Public IP only exists on their upstream router.

LAN Subnets to connect:
Sangfor Device : 10.136.201.0/24 ↔ CISCO Router: 10.102.1.0/24

Tunnel Parameters agreed on both sides:
- IKEv1 Aggressive Mode, AES256/SHA, DH Group 2, NAT-T enabled
- IPSec ESP AES256/SHA, PFS2
- Authentication via PSK & FQDN ID

On Sangfor side:
- IPSec tunnel created + NO-NAT policy configured
- Static peer mode failed (no IKE response) — expected due to NAT
- Cisco suggested dial-up style (Cisco initiates, Sangfor as responder)
- NGAF does not have explicit "Dial-Up", only Static / Dynamic IP / Dynamic Domain
- Currently configured as:
Peer Type = Dynamic IP, Initiator = Off → expecting Cisco to initiate.

Questions:
- Is Dynamic IP peer mode the correct approach to make NGAF act as an IPSec responder for NATed Cisco peers?
- Any additional settings required for successful negotiation in this scenario?
- Any recommended best practices/log monitoring for Dynamic IPSec peers on NGAF?
- Appreciate if anyone has done similar Cisco → NAT → Sangfor NGAF setup and can share insights.

Thanks!

By solving this question, you may help 955 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

ilham Lv2Posted Dec-08-2025 11:01
  
HI Fajri.
you should create VIP for sangfor side and cisco router upstream side.
also dont forget to create NAT policy on both side

I Can Help:

Change

Moderator on This Board

43
6
2

Started Topics

Followers

Follow

1
148
3

Started Topics

Followers

Follow

900
179
94

Started Topics

Followers

Follow

Board Leaders