VPN IP Addresses and NAT.....

Feb 04, 2009 2 Replies

Hello all.



I am working on my remote access VPN (ASA 5505) set up and am about ready to try a couple of new users with it. But have a few questions before doing this.



I have an IP Pool set up on the ASA 5505 for the VPN Clients. It's



192.168.5.95-115. I am "blocking off" this same range on our internal network (192.168.16.0/24). I currently have a Static NAT configured for .95 for my testing.

Is there a way to do all of these in one fail swoop or do I need to do each one individually? Since I only have a small number copying and pasting won't be bad, but if I can do them in one statement that would be nice.



TIA.



Tim


Excel is a wonderful tool for this... I use it to build replicated strings...

Scott

Well that might be one way however:-

I am honestly not sure exactly what you want to do but cisco does support NAT ranges so that for example

192.168.1.96-127 can get mapped one for one to say 192.168.10.96-127

I cannot recall exactly the commands however this should point you the correct way.

formatting link
"Match Host

The ability to configure NAT to assign the same Host portion of an IP Address and only translate the Network prefix portion of the IP Address. Useful where you are using the host portion as a means to identify or number users uniquely."

Note that I have chosen the addreses *CAREFULLY*. Your range 95-115 are not a 'round numbers' in binary.

My one is:) You can also just do dynamic pool NAT where the NAT addresses are assigned randomly from a pool.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required