Configuring the IKE NAT keepalive feature
About the IKE NAT keepalive feature
If IPsec traffic passes through a NAT device, you must configure the NAT traversal feature. If no packet travels across an IPsec tunnel in a period of time, the NAT sessions are aged and deleted, disabling the tunnel from transmitting data to the intended end. To prevent NAT sessions from being aged, configure the NAT keepalive feature on the IKE gateway behind the NAT device to send NAT keepalive packets to its peer periodically to keep the NAT session alive.
Procedure
Enter system view.
system-view
Set the IKE NAT keepalive interval.
ike nat-keepalive seconds
The default interval is 20 seconds.