SiteA to SiteB IPsec VPN and SiteA to SiteC, but SiteB and SiteC have the same IP Range

Hi Group

I try to build a 2nd IPSec Tunnel from SiteA to SiteC, but SiteC have the same IP Address Range like SiteB:

SiteA: 192.168.2.0/24 / PIX OS 8.0(2) SiteB: 192.168.33.0/24 / PIX OS 6.3(5) SiteC: 192.168.33.0/24 / PIX OS 6.3(5)

The tunnel from A to B is up and runs fine.

I want to translate to Adresses for the SiteC on the PIX on SiteA (192.168.233.0 [SiteA] > 192.168.33.0 [for SiteC]) and i saw this example:

formatting link
I play arround with this example, but i don't want to translate on the PixA (SiteA) the 192.168.1.0 to 172.18.1.0, i want to translate on the PixA the Address 10.1.0.0 to 172.18.1.0 for example. Sometimes i loos the connection to SiteB, but i never bring up the tunnel to SiteC.

Is there anyone who can give me a tip how i need to build the access- list and static statement?

Thank you lot.

ivo

Reply to
googlegroups
Loading thread data ...

formatting link

You need to do the NAT on site C's Pix not site A's.

Reply to
Brian V

Thank you Brian

When i define the NAT on SiteC, it works. Is there no chance to do that on SiteA?

Reply to
googlegroups

Not without getting very ugly in the config. I.E. addding an additional outside interface to Pix A, moving NAT to the internet router, subnet specific routing, etc.... The problem is that Site A has no way to differentiate what site gets NAT'd, you have a single "nat (inside,outside)" which covers both destination subnets.

Reply to
Brian V

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.