Re: [fw-wiz] VPN NAT issue



you will need a static nat or nat exemption. You are trying to access from
a low security interface to a higher one so put a translation in for the
173.16 net to the vpn pool either by static or nat0. For the static it
would be IN2 int to OUT and for nat0 apply it to IN2 where the rules
stipulate the src from IN2 net to the vpn local pool. Also apply the acl
entries allowing this traffic to the outside acl. Let me know if you have
any issues.

Kevin

On Wed, Nov 12, 2008 at 4:52 AM, Vladislav Antolik <
vladislav.antolik@xxxxxxxxx> wrote:

Hello,

I'm using Cisco PIX 515E with 8.0(3) image.
I have 3 networks.
IN 172.16.0.0/16
IN2 <http://172.16.0.0/16IN2> 173.16.0.0/16
OUT 174.16.0.0/16.
VPN local pool is 10.0.0.0/28.
I'm using remote access VPN to reach IN servers without problems(I
used howto from Cisco pix conf. guide)

I would like to reach IN2 servers too, but I don't know to setup NAT
from vpn pool to this network(IN2).
I this network (IN2) my VPN hosts(10.0.0.0/28) must be translated.

I tried
nat (OUT) 66 10.0.0.0 255.255.255.240
global (IN2) 66 173.16.0.5
but this doesn't work.

Is any possibility to translate VPN pool?

Many thanks
Vladislav
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards


Relevant Pages

  • Re: [fw-wiz] VPN NAT issue
    ... an acl is needed for vpn traffic. ... If you allow the vpn pool ips in from the outside how would the ... would be IN2 int to OUT and for nat0 apply it to IN2 where the rules ...
    (Firewall-Wizards)
  • Re: [fw-wiz] VPN NAT issue
    ... You need to use a static rule then ... Access-list IN and Access-list IN2 ... are bound to the interface by Access-Group IN and Access-Group IN2. ... VPN local pool is 10.0.0.0/28. ...
    (Firewall-Wizards)
  • Re: [fw-wiz] VPN NAT issue
    ... never needed an ACL to allow in VPN traffic on ... Please note that I said outside interface, I do believe if you are ... If you allow the vpn pool ips in from the outside how would the ...
    (Firewall-Wizards)
  • Re: Bizzare split tunnel issue on Pix..
    ... >>VPN works great with the exception of DNS. ... >>Small customer with no internal DNS or WINS. ... >>I had to change the VPN pool from a different subnet to ...
    (comp.dcom.sys.cisco)
  • Re: [fw-wiz] VPN NAT issue
    ... You want a NAT exemption on the IN2 interface ... I'm using Cisco PIX 515E with 8.0image. ... VPN local pool is 10.0.0.0/28. ...
    (Firewall-Wizards)