NAT routing for VPN client

Unanswered Question
Feb 9th, 2007


I have a Cisco 2801 router connected to the Internet running EasyVPN server and some site-to-site connections.

Some of the clients from the EasyVPN server need to be able to 'use' the IP from the 2801 to access other servers in the public internet. So I'm trying to setup NAT routing but I cannot get it to work.

On the EasyVPN server tunneling is disabled (for now) and the address pool assigned to the clients has been added to the permit pool of the NAT routing.

But I think that my problem is that requests from a VPN client come from interface FastEthernet0/0 and that is the public interface on which they are leaving again as well. And to my knowledge I cannot set an interface to "inside" and "outside" in the NAT settings.

Please help.

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
marketgraph Thu, 02/15/2007 - 09:24

Sorry but it didn't help. This is a situation where you want to NAT traffic on each router itself. What I need to accomplish is have two networks, A and B. Both connected to the public internet but all traffic to the public internet coming from network B should be first routed using an IPsec tunnel to network A, and on network A NAT routing should take place to route the traffic to the outside world.

Thing is that from the Cisco IOS side, the incoming VPN traffic is on the same interface, FastEthernet 0/0 as the public network, such that it seems like it is not applying any NAT rules to it.


This Discussion