In the latest firmware revisions for Vigor Routers, the IPSec pass-through function is disabled by default since it conflicts with the new NAT-T feature.


Cisco VPN3002 creates a VPN connection to a Cisco Concentrator at a remote location on the internet. IKE packets are going in & out of the VPN3002, but IPSec packets are not passing through the Vigor2800 router.



To allow VPN pass-through on the DrayTek router, you will need to carry the steps described below in the router configuration:





Telnet to the router and add the following command:

“‘srv nat ipsecpass on’.

To view the IPSec pass-through status enter the following command:

“srv nat ipsecpass status”