Re: [fw-wiz] VPN NAT issue
- From: "Dave Love" <dlove@xxxxxxxxxxxxxxxxxxxxxx>
- Date: Wed, 26 Nov 2008 08:18:48 -0600
Those commands do not allow access. You need to use a static rule then
provide an access list. They should be the same as the other ones with
different numbers and also apply the access-list to the other interface
using a different name. Forexample, Access-list IN and Access-list IN2
are bound to the interface by Access-Group IN and Access-Group IN2.
I've attached a document that shows the rules. It's a little old but
still relevant.
I think this is what you are asking.
-----Original Message-----
From: firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx
[mailto:firewall-wizards-bounces@xxxxxxxxxxxxxxxxxxxxx] On Behalf Of
Vladislav Antolik
Sent: Wednesday, November 12, 2008 3:52 AM
To: Firewall Wizards Security Mailing List
Subject: [fw-wiz] VPN NAT issue
Hello,
I'm using Cisco PIX 515E with 8.0(3) image.
I have 3 networks.
IN 172.16.0.0/16
IN2 173.16.0.0/16
OUT 174.16.0.0/16.
VPN local pool is 10.0.0.0/28.
I'm using remote access VPN to reach IN servers without problems(I
used howto from Cisco pix conf. guide)
I would like to reach IN2 servers too, but I don't know to setup NAT
from vpn pool to this network(IN2).
I this network (IN2) my VPN hosts(10.0.0.0/28) must be translated.
I tried
nat (OUT) 66 10.0.0.0 255.255.255.240
global (IN2) 66 173.16.0.5
but this doesn't work.
Is any possibility to translate VPN pool?
Many thanks
Vladislav
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
Attachment:
connectivity.pdf
Description: connectivity.pdf
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
- References:
- [fw-wiz] VPN NAT issue
- From: Vladislav Antolik
- [fw-wiz] VPN NAT issue
- Prev by Date: Re: [fw-wiz] VPN NAT issue
- Next by Date: Re: [fw-wiz] Cisco ASA IKE Initiator unable to find policy
- Previous by thread: Re: [fw-wiz] VPN NAT issue
- Next by thread: Re: [fw-wiz] VPN NAT issue
- Index(es):
Relevant Pages
|