Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

PIX: NAT before IPSec

Hi,

We're building a LAN-to-LAN IPSec VPN between a PIX and a 3015 Concentrator.

The soure LAN (behind the PIX) uses the same private IPs than the destination LAN (behind the concentrator). We thought of NATing the private addresses of the client LAN on the outside interface of the PIX (PAT). Is this address translation performed before entering the tunnel ?

Any other ideas to solve the problem are welcome.

Thanks

Dirk

2 REPLIES
Cisco Employee

Re: PIX: NAT before IPSec

Hi Dirk,

You should be able to get this working by doing static one to one NAT for the entire network, for getting an idea kindly look through the following sample config: http://www.cisco.com/warp/public/707/same-ip.html

The NAT happens before the actual IPSec so we can do NAT and then IPSec and this would work without a problem.

Hope this helps,

Regards,

Aamir

-=-=-

New Member

Re: PIX: NAT before IPSec

Hi Aamir,

we tried it an it works fine.

Thanks for your help.

Regards

Dirk

123
Views
0
Helpful
2
Replies