Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN to a PIX (6.3.1) Behind NAT Device

I have a VPN Set up from a PIX behind a NAT device running 6.3.1 to a VPN Concentrator. The lan to lan VPN works fine (connecting as base group to the concentrator).

Now, I would like to do two things. First, I would like to terminate client sessions to the PIX. I have passed UDP 500 and 4500 through the NAT device provided by my ISP (Broadmax DSL Modem/Router), but cannot get the VPN Client to connect. I do have "isakmp nat-traversal" turned on.

I would also like to do a true lan to lan with shared key, but am not sure I can originate from the VPN 3000 side if the PIX side is behind a NAT device.

Will either of these scenarios work?? If so, what do I need to do to get them to work??


Re: VPN to a PIX (6.3.1) Behind NAT Device

This doc seems to have a similair topology to your requirement, take a look,