[fw-wiz] Re: firewall-wizards digest, Vol 1 #1180 - 6 msgs
gcisternas_at_acapomil.cl
Date: 01/21/04
- Previous message: Javier Sanchez: "[fw-wiz] Pix vpns nat"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: <firewall-wizards@honor.icsalabs.com> Date: Wed, 21 Jan 2004 09:03:43 -0300 (CLST)
> From: Allendes Fernando <fallendes@atichile.com>
> To: "'firewall-wizards@honor.icsalabs.com'"
> <firewall-wizards@honor.icsalabs.com> Date: Mon, 12 Jan 2004 19:28:39
> -0300
> Subject: [fw-wiz] NAT inside a VPN between PIX and Cisco device
>
> Hello:
> We are trying to make a VPN between PIX and Cisco device, but using
> NAT with the PIX external IP. The picture is like:
> Internal IP ----> PIX (NAT) ----> Internet ----> Cisco Router --->
> "Routeable IP"
> Because the Cisco Router have internal and routeable networks, then
> we must make a VPN from PIX using NAT inside the VPN.
> At least, we set up such VPN but using two external IPs in the PIX. Do
> you know how we can do it using only one external IP in the PIX ?
>
> Regards,
> Fernando Allendes.
Hi all:
Lets see (X) <---> (NAT) <===> (Inet) <===> (Cisco) <---> (Dest)
--- Uncyphered flow
=== cyphered flow
This is an idea only.
Maybe your VPN was configured in Tunnel mode. This is because the packets
in tunnel mode when arrives to the (Cisco)<--->(Dest) segment are
unruteables because its adresses arenīt valid outside X's network. If this
would be possible to implement, It would need the route from (Dest) to the
external IP of (NAT), and a rule in (NAT) wich will translate it packet
dest ip to the X known IP, and in this scenario the (NAT) box will need an
extra IP in order to translate only that VPN-Redirection configuration.
So, try to configure the VPN in transport mode. Maybe in that way you
could save one external IP.
Regards.
G.C.
_______________________________________________
firewall-wizards mailing list
firewall-wizards@honor.icsalabs.com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
- Previous message: Javier Sanchez: "[fw-wiz] Pix vpns nat"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|