cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1013
Views
0
Helpful
2
Replies

vpn and nat

rehan_uet
Level 1
Level 1

i have two networks with private ip address scheme and i want to connect them throug IPsec vpn tunnel, so when i will configure ipsec on both the sides do i need to configure nat or it will work without configuring nat.

2 Replies 2

gfullage
Cisco Employee
Cisco Employee

Generally you make the IPSec packets bypass NAT, so that each IP address appears as its original address on the other LAN. This way your access-list that defines the encrypted traffic will say "FROM private net TO private net", and your NAT access-list will say "DON'T NAT private net TO private net but DO NAT private net TO anything else".

You don't say what your devices are so I can't help you much more. There's a plethora of sample configs for IPSec here though:

http://www.cisco.com/pcgi-bin/Support/browse/psp_view.pl?p=Internetworking:IPSec&s=Implementation_and_Configuration

Hi,

I have a question concerning " NAT per-destination-VPN":

from a given site (my site), there are many IPSEC VPNs created to other sites via the internet (site-to-site VPNs). I would like to NAT my site ip adresses, only for a given destination site, and no NAT for others. there might be other constraints as to NAT with different IP ranges for different destination VPNs.

How do we do that?

Thanks. Madjid

Review Cisco Networking products for a $25 gift card