Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

IPSEC b/w ASA and Router --- with nat stuff

I need help regarding the following issue..

An asa is connected to a router which is connected to the internet.

A vpn must be established b/w ASA and a router that is over internet . The ASA is not directly connected to the internet. It is connected to a router which nat the Asa outside ip to a static global IP .

All i need to know is that do need any special configs for this . or its the same as if ASA would have been directly connected to the internet


Re: IPSEC b/w ASA and Router --- with nat stuff

In order to configure a LAN-to-LAN tunnel between a Cisco IOS? router and an Adaptive Security Appliance (ASA), these configurations are required on the ASA:

Configure the crypto ipsec command in Phase 2.

Configure the isakmp policy command.

Configure the nat 0 command and the access-list command in order to bypass NATting.

Configure the crypto-map command.

Configure the tunnel-group DefaultL2LGroup command with group information