Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

LAN to LAN VPN and SSH port forwarding

Hello All,

I was wondering if someone can help me with the following: I would like to be able to do SSH port forwarding from outside to an IP address inside. Normally, this is very straighforward. The problem now is that if I do so, then the LAN to LAN VPN stops working!

Here are the details:

There is a LAN to LAN VPN working flawlesly (so far) between an ASA 5505 and a Cisco 861 Integrated Router. However, I would like also, to give SSH access to an IP address behind the Cisco router. The moment I do this the VPN breaks!

I attached the Cisco 861 router configuration, where the problem shows. The ASA has public IP X.X.X.105 and the router has X.X.X.105. These two are used for the VPN tunnel. The internal network in the ASA is and in the router. These talk to each other using the tunnelt.

But, the moment I try to forward port 22 in the router from X.X.X.107 to the VPN breaks! I do that with the following line:

ip nat inside source static tcp 22 X.X.X.107 22

Obviously, something is eluding me. The configuration is rather short and simple. But, I'm a newbie with Cisco rotuer configuration. Note that the tunnel stays up after I use the natting entry and I can talk from the router to the ASA, but not the other way around!

The router is Cisco 861 with IOS version 15.0(1)M7.

What could be the problem?



New Member

LAN to LAN VPN and SSH port forwarding

CreatePlease login to create content