Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

IPsec VPN with Static Nat and Route-Maps

I am trying to setup a site to site vpn with a vendor. Om my end I have a Cisco 3825 router running 12.4 IOS. I am doing static nat translations for 3 internal hosts. I have been trying to test this in my lab, but am running into some issues. When I setup the VPN with the static nat translations it works just fine I I only use 1 host, I have encaps and decaps and the vpn is great, but when I use more that 1 hosts I have issues with the VPN not working properly. I am also using a route-map that calls my static nat translations and ACL's. I am attaching a config from my lab of both test routers.


Re: IPsec VPN with Static Nat and Route-Maps

To configure static NAT with the route-map option, issue the ip nat inside source static local-ip global-ip route-map map-name command from global configuration mode. Identify the NAT inside and outside interfaces by issuing the ip nat inside command and the ip nat outside command under the specific interface configuration mode. The route-map should be configured to match the specific traffic that needs to be translated by issuing the match command.

For example, a router connects to the Internet through interface serial 0 and is connected through interface serial 1 to a partner network which uses the address space. The LAN interface of the router is connected to the corporate inside network which belongs to the network. The requirement is that an inside host, which could be a mail server, should be translated to address when communicating with the Internet. The same host should be translated to the address when communicating with the partner network. This is the relevant configuration on the router:

interface Ethernet0

ip address

ip nat inside