Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

lan to lan nat question - concentrator 3005

I have set-up a lan to lan vpn tunnel an it is established. However, I am unable to pass traffic. I believe it has to do with nat. When the remote side sends traffic it is sent from to I have set-up the following lan-to-lan nat rule on my side:

Source Network: wildcard mask ( is the inside of my 3005)

Translated Network: wildcard mask

Remote Network: wildcard mask ( is my lan)

My PIX logs the following:

2005-10-25 19:21:18 UTC Local7.Warning %PIX-4-106023: Deny tcp src vpn: dst outside: by access-group "vpn"

2005-10-25 19:21:18 UTC Local7.Info %PIX-6-110001: No route to from

What am I missing? Thanks for any assistance.



Re: lan to lan nat question - concentrator 3005

The problem may be due to followign reasons.

Cannot establish a LAN-to-LAN VPN tunnel to a PIX Firewall due to a invalid local address. ...

In LAN-to-LAN VPN tunnel on router, packets exceeding 1500 maximum transmission units (MTU) are dropped. User cannot access a server across a LAN-to-LAN VPN tunnel and needs to bypass static translation for VPN traffic. LAN-to-LAN tunnel not established. The pre-shared keys don't match. Core issue, The pre-shared keys don't match

CreatePlease to create content