Any user from inside sends traffic to 172.31.9.xx which in turns initiates the tunnel through VPN Concentrator User can start the tunnel by sending traffic to actual IP 126.96.36.199 also from LAN
After I moved the configuration from PIX 515 to ASA 5510 I can send the traffic through 172.31.9.xx but not through 191.2.1.xx(Actual IP) Logs on ASA shows "No Translation group found icmp src inside 172.20.xx.xx dst VPN 191.2.1.xx (type 8,code 0) If I remove the static NAT from ASA it starts sending traffic through actual IP 191.2.1.xx
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...