[ASK] IPSec Sangfor NGAF ↔ Cisco 881 Behind NAT (Dynamic/Dial-up Scenario)

Fajri Rohmana Lv1Posted Dec-06-2025 19:44

Hi everyone,

I’m working on an IPSec Site-to-Site VPN between Sangfor NGAF M5400 (FW 8.0.39) and a Cisco 881 router, but the Cisco side is behind a NAT gateway and has no direct public IP. Public IP only exists on their upstream router.

LAN Subnets to connect:
Sangfor Device : 10.136.201.0/24 ↔ CISCO Router: 10.102.1.0/24

Tunnel Parameters agreed on both sides:
- IKEv1 Aggressive Mode, AES256/SHA, DH Group 2, NAT-T enabled
- IPSec ESP AES256/SHA, PFS2
- Authentication via PSK & FQDN ID

On Sangfor side:
- IPSec tunnel created + NO-NAT policy configured
- Static peer mode failed (no IKE response) — expected due to NAT
- Cisco suggested dial-up style (Cisco initiates, Sangfor as responder)
- NGAF does not have explicit "Dial-Up", only Static / Dynamic IP / Dynamic Domain
- Currently configured as:
Peer Type = Dynamic IP, Initiator = Off → expecting Cisco to initiate.

Questions:
- Is Dynamic IP peer mode the correct approach to make NGAF act as an IPSec responder for NATed Cisco peers?
- Any additional settings required for successful negotiation in this scenario?
- Any recommended best practices/log monitoring for Dynamic IPSec peers on NGAF?
- Appreciate if anyone has done similar Cisco → NAT → Sangfor NGAF setup and can share insights.

Thanks!

By solving this question, you may help 961 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

ilham Lv2Posted Dec-08-2025 11:01
  
HI Fajri.
you should create VIP for sangfor side and cisco router upstream side.
also dont forget to create NAT policy on both side
Newbie664270 Posted Feb-03-2026 11:24
  
Thank you so much!

I Can Help:

Change

Moderator on This Board

1
148
3

Started Topics

Followers

Follow

918
183
94

Started Topics

Followers

Follow

Board Leaders