Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

VPN Client with NAT to a dmz

Usually we configure on the PIX the remote VPN clients without NAT (no nat) when they talk to machines on the inside interface or dmz. So when the host on the dmz answers to the VPN client, it's to his real address.

Now I like to have the VPN client source adress being translated to an adress belonging to the dmz network. Is this ever possible ?

example :

PIX outside interface : W.X.Y.Z

PIX dmz interface :

VPN Client : (address is given by a pool from the PIX)

On the dmz there is a host (

When is talking to, I would like to have that:

source address translated to (as for example)

The host sends back a packet to destination address and the PIX will translate it back to

If this is possible, i would like to have an example of the config.

I've configured a lot of different scenarios, but when doing a ping from the VPN client, I always see on the PIX logs "No translation group found for icmp src outside: dst dmz2: (type 8, code 0)"

Thanks for help

New Member

Re: VPN Client with NAT to a dmz

Not very sure it will work or not...

Don't do translation, go into dmz as


static (outside,dmz) netmask

you might need access list....

Please let me know....