Site-to-site VPN with NAT

Can I construct a site-to-site VPN between 2 PIX 501's and use a natted network between the sites? Is this possible with ver 6.x software or do I need ver7.x?

JHG

Reply to
jhgraves
Loading thread data ...

Yes.

If the network uses one-to-one NAT, then you can do it using any release supported on the 501.

If the network uses PAT (Port Address Translation) then you need PIX 6.3 and you need "isakmp nat-traversal 20"

BTW, PIX 7.x is not supported on the 501 and likely will never be.

Reply to
Walter Roberson

Adding to Walter's reply:

Configure the pixes normally, Then configure VPN normally without using the NAT. If that is working. Configure NAT. Remember to use the natted addresses in the crypto acl.

-Vikas

Reply to
sampark

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.