cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
783
Views
5
Helpful
1
Replies

L2L IPsec VPN with Policy NAT

allen.malanda_2
Level 1
Level 1

Hello All,

I am having some issue with L2L IPsec with policy nat. I can not ping any host on both side of the tunnel. Tunnel is establish with no problem but there is no traffic going through. If I take off the policy nat, everything works fine. How can I make it work with policy nat. I've attached the configuration for both asa. Attachment file name - bothASAconfig.txt.

Please help!

Thanks,

1 Reply 1

acomiskey
Level 10
Level 10

When you add the policy nat you need to remove the nat exemption. Nat exemption always happens first, so as long as it's there, your policy nat won't happen.

no access-list inside_nat_exempt extended permit ip 10.1.0.0 255.255.255.0 10.198.0.0 255.255.255.0

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: