Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

IPsec VPN site to site with nat in both ends

Hello, I'm currently configuring a site-to-site IPsec VPN and both ends have NAT configured. The topology is something like this:

[LAN]-----10.145.XX.XX-----[ISA]-----172.17.1.0 ---[ROUTER] -----IPSEC----- [ROUTER] ---192.168.10.xx----[LAN]

The goal is obviously to reach 10.145 and 192.168 back and forth.

I can establish the first IKE phase and I see the peers, I even can see traffic being decrypted and not encrypted with the "show crypto ipsec sa" command. I configured both 172.17 and 10.145 just because traffic form both networks can go through the tunnel.

I attach the configs so you can see my actual conifguration, I will also put the output of some commands.

349
Views
0
Helpful
0
Replies