We're in the process of establishing a VPN tunnel to a business partner who wants us to NAT down the created tunnel translating both source and destination addresses. We use OSPF in a single large area to manage our routing and do static routes as little as possible if at all. I think I have a weird problem with what they are asking me to do (they're flat and statically route) but I could be wrong/confused.
[Our ASA 5500] -------- [ Our 3845 Router] -------------------( CAT PICTURES (INTERNET) ) ------------ [ Their ASA they only use as a VPN endpoint ]----[SRX]
I have IPSEC configured on the 3845 router to create a tunnel to them. I also have a static route for the 172.31.1.0/24 address that they are exposing as NATted destination IPs for us. I have a NAT rule on the ASA which translates packets sent to the destination 172.31.1.0/24 and gives them the source 172.16.89.0/24 which is the only source they'll accept from. The tunnel interface has been raised with no shutdown, but line protocol is down because no interesting traffic has attempted to traverse it yet. The reason no interesting traffic has attempted to traverse it, is because there is no route to it, because distributing the static route into OSPF can only happen once the tunnel interface is up and the route is active, which doesn't happen until traffic gets to it.... you get the idea.
Have I misunderstood something or can a route to a tunnel not be distributed into OSPF because until traffic is routed to the tunnel it won't raise?
Hi everyone, I would like to thank you in advance for any help you can provide a newcomer like myself!
Im studying the 100-105 book by Odom and am currently on the topic of Port security. I purchased a used 2960 and I'm trying to follow a...
While deploying a number of 18xx/2802/3802 model access points (APs), which run AP-COS as their operating platform. It can be observed on some occasions that while many of their access points were able to join the fabric WLC withou...
I am going to design and build an LAN network under a tunnel underground with long distance between the switches.
I will have 2 Catalyst switches and 8 Industrial IE3000, and they will be connected with fiber.
For now I am planning on use Layer-2 s...