cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
706
Views
3
Helpful
4
Replies

PIX NAT traffic towards an ipsec peer

James Lasky
Level 1
Level 1

Hi,

is there a way to NAT the source ip address of a traffic going towards a specific ipsec peer (not towards internet) ?

If yes, could you pls provide me an example or a url ?

Tks

Ric

4 Replies 4

acomiskey
Level 10
Level 10

y.y.y.y = original source address

z.z.z.z = destination address

x.x.x.x = NAT address

access-list policy_nat permit ip host y.y.y.y host z.z.z.z

static (inside,outside) x.x.x.x access-list policy_nat

Does this means that NATTing is done before routing and encryption ?

Tks

no, the order is :

routing

NAT

encryption

HTH

Hi,

Below is the URL that explains this set up in detail

PIX/ASA 7.x and later: Site to Site (L2L) IPsec VPN with Policy NAT (Overlapping Private Networks) Configuration Example

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9950.shtml

Regards,

Arul

*Pls rate if it helps*

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: