Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Use Static PAt to pass IPSEC ESP through Pix

I am trying to pass a vpn through a pix firewall using pat. I have found examples using NAT but don't have a free public IP to use. I have found examples for how to do this in IOS but not the PIX.

Looking for PIX equivilent to these IOS commands.

ip nat inside source static esp <internal IP> <external IP>

ip nat inside source static udp <internal IP> <external IP> 500

I can do the second command easily but cannot find the right syntax for the command to forward esp.

1 REPLY
New Member

Re: Use Static PAt to pass IPSEC ESP through Pix

Sorry guys figured it out myself. I need to use NAT-T to encapsulate the esp packets as UDP 4500 and use pat to forward those packets.

See http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094ecd.shtml#t5

For a configuration example. After actualy reading the entire article it made sense.

243
Views
0
Helpful
1
Replies