Static 1 to 1 NAT config needed through Cisco PIX IP Sec VPN Tunnel

Jan 10, 2007 7 Replies

Hi all



Now I'm using a dynamic NAT config in a IP SEC VPN LAN-2-LAN through a PIX. I want to create a complete new config where the client are natted whitout using the original destination IP address



client--[routed-net]--[PIX2]--IP-SEC-VPN--[PIX2]--hostsegment--[host-10.1.1.1]



Static NAT pool Client 10.220.0.1 connects to 10.96.40.1 and will be connected to host



10.1.1.1 Client 10.220.0.2 connects to 10.96.40.2 and will be connected to host
10.1.1.2

How to setup a static nat (pool) for this combination, where 10.96.40.254 is the inside IP addres of PIX2.



Could you please help me?



regards Proza


Could you repost, re-explaining what you want to do? I don't seem to catch what you are talking about when you reference the destination IP address, and I don't understand what you are saying about this client "connecting" to that address ?

[Note: I tried to send this request for clarification through email, but your return address is non-functional.]

Client--[routed-net]--[PIX1]--IP-SEC-VPN--[PIX2]--hostsegment--[host-10.1.1.1]

Client 10.220.0.1 need to reach host 10.1.1.1 without using the destination host address 10.1.1.1 directly. For that I want to use a "NAT pool" on the inside interface of PIX1 (10.96.0.254). So for real the client 10.220.0.1 connects for example to 10.96.0.1 (= NATted host 10.1.1.1)

[Note: You can use the e-mail address, after the whipe out the part "magweg"]

Hi Proza. Have you found a solution as this is exactly what I want to do also.

Thanks

Hi Nera

No solutions found yet, still busy on it

What is your application for this? Are you trying to address routing issue on the inside network?

proza wrote:

http access to Oracle application, to an inside address.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required