Advertisement

05.22.2008 at 12:13PM PDT, ID: 23425600
[x]
Attachment Details

PIX NAT question

Asked by js479 in Networking Hardware, Virtual Private Networking (VPN), Networking Hardware Firewalls

Tags: PIX, cisco, ios, networking

I'm struggling through setting up a new VPN and the issue I've run into now is the NAT rules. On my pix that will host 2 VPNs I tried to set up to nat rules but the new nat rule is overwriting previous one.

So the existing nat rules with 1 VPN looked like this:
global (outside) 76 interface
nat (inside) 0 access-list inside_outbound_nat0_acl
nat (inside) 76 10.10.1.0 255.255.255.0 0 0
nat (DMZ1) 76 192.168.100.0 255.255.255.0 0 0

I'm trying to add a no nat rule for the new VPN via:
nat (inside) 0 access-list nonatny
but this rule overwrites the other nat (inside) 0 rule.
What am I doing wrong here and how can I no nat for both access lists?Start Free Trial
 
 
[+][-]05.22.2008 at 12:57PM PDT, ID: 21627037

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]05.22.2008 at 01:57PM PDT, ID: 21627565

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]05.22.2008 at 03:39PM PDT, ID: 21628217

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Networking Hardware, Virtual Private Networking (VPN), Networking Hardware Firewalls
Tags: PIX, cisco, ios, networking
Sign Up Now!
Solution Provided By: arnold
Participating Experts: 2
Solution Grade: A
 
 
[+][-]05.22.2008 at 03:50PM PDT, ID: 21628275

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.03.2008 at 12:29PM PDT, ID: 21703707

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.03.2008 at 12:31PM PDT, ID: 21703719

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_EXPERT_20070906