site2site ipsec with nat
I have to build a ipsec tunnel between 2 pix 515 firewalls, nothing special. But the private ip range of site A needs to be translated to another private ip range before being able to connect to site B through the ipsec tunnel. private range site A 192.168.1.0 /24 needs to be translated to
172.16.1.0 /24 because private range site B 172.16.2.0 /24 only allow the subnet 172.16.1.0 /24 to connect. So NAT only should be done for the IPsec tunnel between site A and B. For other ipsec tunnels packages should not be translated. Is this possible and how? Can anyone help me? Thanks already. read more and respond »Posted 5 years ago by chackamakka in Cisco Systems