Re: [fw-wiz] PIX515 Inside NAT to private addresses through P2PTunnel
- From: Chris Myers <clmmacunix@xxxxxxxxxxx>
- Date: Thu, 4 Sep 2008 17:13:52 -0500
Will you be having bi-directional traffic? If so, then you will need to do the reverse of this in the other direction. Outbound you need to source NAT your 10.195.x.x (i.e local network) addresses to say 10.2.2.x, so the remote network does not see the src as its own subnet, so they can traverse the tunnel. All your other subnets will not have to source NAT because they do not overlap. Although, you will then need to use another IP scheme to destination NAT to the 10.195.x.x on the other side, so all your local nodes on your network are talking to another subnet other than 10.195.x.x (i.e. remote network), but the PIX is translating it to a 10.195.x.x so the other side knows where to send the packet over the tunnel. Chris Myers John 1:17 For the Law was given through Moses; grace and truth were realized through Jesus Christ. On Aug 26, 2008, at 1:02 PM, Dave Arroyo wrote:
|
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- References:
- [fw-wiz] PIX515 Inside NAT to private addresses through P2PTunnel
- From: Dave Arroyo
- [fw-wiz] PIX515 Inside NAT to private addresses through P2PTunnel
- Prev by Date: Re: [fw-wiz] VPN/DMZ problem
- Next by Date: Re: [fw-wiz] PIX 6.1 xlate issues
- Previous by thread: [fw-wiz] PIX515 Inside NAT to private addresses through P2PTunnel
- Next by thread: Re: [fw-wiz] PIX515 Inside NAT to private addresses through P2PTunnel
- Index(es):