Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PIX with IPSec tunnel and NAT on tunnel

We're using a PIX to build multiple IPSec tunnels to custommers.

Some of these custommers have overlapping IP networks.

The normal config of an IPsec tunnel is an "no_nat_acl" ACL and a statement to exclude IPSec traffic from NAT.

Is it possible to do NAT on a IPsec tunnel between two PIX firewalls?

Regards,

Godfried Boshuizen

The VisionWeb

1 REPLY
ovt Bronze
Bronze

Re: PIX with IPSec tunnel and NAT on tunnel

Yes and No.

Yes, it is possible in general.

No, there are many corner cases. The most difficult problem is NAT'ing VPN traffic and Internet traffic simulteneously to different addresses. At least 6.3(2) is required for that, but this version is broken and deleted from the CCO.

Oleg Tipisov,

REDCENTER,

Moscow

93
Views
0
Helpful
1
Replies