Re: [fw-wiz] VPN NAT issue

Those commands do not allow access. You need to use a static rule then
provide an access list. They should be the same as the other ones with
different numbers and also apply the access-list to the other interface
using a different name. Forexample, Access-list IN and Access-list IN2
are bound to the interface by Access-Group IN and Access-Group IN2.

I've attached a document that shows the rules. It's a little old but
still relevant.

I think this is what you are asking.

-----Original Message-----
From: firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx
[mailto:firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx] On Behalf Of
Vladislav Antolik
Sent: Wednesday, November 12, 2008 3:52 AM
To: Firewall Wizards Security Mailing List
Subject: [fw-wiz] VPN NAT issue


I'm using Cisco PIX 515E with 8.0(3) image.
I have 3 networks.
VPN local pool is
I'm using remote access VPN to reach IN servers without problems(I
used howto from Cisco pix conf. guide)

I would like to reach IN2 servers too, but I don't know to setup NAT
from vpn pool to this network(IN2).
I this network (IN2) my VPN hosts( must be translated.

I tried
nat (OUT) 66
global (IN2) 66
but this doesn't work.

Is any possibility to translate VPN pool?

Many thanks
firewall-wizards mailing list

Attachment: connectivity.pdf
Description: connectivity.pdf

firewall-wizards mailing list

Relevant Pages

  • Puzzling VPN problem with Windows 2003
    ... I have a standard IPSEC VPN running between two 837s using a shared secret. ... access-list 23 permit ... access-list 111 permit tcp any host eq 21 ...
  • Setting the MTU
    ... I've been getting odd problems with a VPN between two 837 routers and it's ... access-list 23 permit ... access-list 111 permit tcp any host 333.333.333.18 eq 21 ...
  • Re: [fw-wiz] VPN NAT issue
    ... a low security interface to a higher one so put a translation in for the ... net to the vpn pool either by static or nat0. ... would be IN2 int to OUT and for nat0 apply it to IN2 where the rules ... stipulate the src from IN2 net to the vpn local pool. ...
  • Re: [fw-wiz] VPN NAT issue
    ... an acl is needed for vpn traffic. ... If you allow the vpn pool ips in from the outside how would the ... would be IN2 int to OUT and for nat0 apply it to IN2 where the rules ...
  • Cisco 877 NAT and site-site VPN
    ... My internal network is hidden behind the router's static external IP address using NAT. ... Now I am trying to set up a VPN to another company, ... access-list 103 permit ip any ...