×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

PIX NAT

Unanswered Question
Nov 28th, 2006
User Badges:

We have a PIX with 3 interface, 1. Inside, 2. Outside, 3. DMZ.


In the DMZ there is a VPN Concentrator which has a site-to-site VPN with another site. How should I write the nat statements so that all VPN traffic is not natted, but everything else is.


The problem is I have written the ACL, but cannot no nat or NAT0 the ACL because some addresses in it need to be natted.

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
mgaysek Tue, 11/28/2006 - 09:25
User Badges:

Base your no-nat acl on source and destination. This way if the traffic does not match that rule it will be nat'd.

Actions

This Discussion