cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
576
Views
0
Helpful
2
Replies

ASA PAT/hairpin packets destined to external IP address

oldcreek12
Level 1
Level 1

Hi, all,

I have a situation that I am not sure it can be achieved by ASA.

We need to access a website that only allows blessed source IP address, our HQ PAT address is blessed, however our remote office's PAT address is not, so employees in remote office can not access this website unless they do it from machines in HQ through IPsec site2site VPN.

I am thinking to pipe down traffic destined to this website from remote office to site2site IPsec tunnel to HQ, what I am not sure is when traffic reaches HQ ASA, will ASA correctly PAT this packet and hair-pin it to outside interface?

2 Replies 2

acomiskey
Level 10
Level 10

Host ASA

global (outside) 1 interface

nat (outside) 1

same-security-traffic permit intra-interface

access-list extended permit ip host

Remote ASA

access-list extended permit ip host

access-list extended permit ip host

Hi,

Thanks a lot for your help, I made slightly change of your recommended solution, I can not nat outside all remote vpn networks because that will break split tunnel traffic. Anyhow, ping from remote office's office to this website works, traffic is going to the IPsec tunnel to HQ and I can see translation entry created in HQ ASA. However we still can not access the website from remote office. I will update the forum once I resolve this problem.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card