vpn on 2811 with overlapping networks and all natting on one side

Nov 26, 2007 2 Replies
vpn on 2811 with overlapping networks and all natting on one side open original image

Hi,



I have a vpn setup with the same private networks at both sides. We don't control the other vpn peer and my customer wants to do all the natting on his side. With a pix/asa it is possible to nat the source and destination on one side of a vpn setup (bi-directional translation):

formatting link
Has someone done the same setup with a router (2811 with ADVSECURITY)?



Br. Robby


Yup, very simple. Nothing "different" you need to do on your end except add the NAT statements (and build the VPN using the NAT'd IP's instead of your privates). You simply give your peer the NAT'd IP's.

Ok, thanks for the feedback! I will give it a try.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required