Correct. Strange getting only one, but it's a case of their ISP issuing a static mapping through their DHCP servers. This is TELUS btw.
Main Topics
Browse All TopicsHi,
I have a client whos recently purchased a Cisco 2811 to place in front of their ASA firewall to act as a perimeter router. Their Firewall terminates their VPN connection and now since the perimeter router is in place the firewalls Outside interface is no longer internet facing. How do I NAT through an IPSEC VPN connection to the firewall? They dont want to move the VPN termination to the 2811. Also to make matters worse they only have one statically assigned IP.
Ive done this before but simply NATd a whole IP address through since that client had plenty to spare&
Thanks.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
I do not see how you can do this as the NATing on the router will change the hash and thus kill the IPSec tunnel. I would tell your client that they need to get with their ISP and aquire a point to point that they currently have as well as a second small block that they can use to create IPSec tunnel.
So there's no way to foward IPSEC traffic to the external interface of the ASA? I did do this before a simple static NAT rule similar to:
ip nat inside source static [external PIX IP] [External routable IP]
What about something like:
ip nat inside source static tcp [external PIX IP] [IPSEC Protocol(s)] interface FastEthernet0 [IPSEC Protocol(s)]
the above nat statement is not going to work because ipsec is comprised of udp and/or tcp, plus possibly protocol 50 and 51, depending on your config. you can port forward/nat the tcp and udp but not the esp (50) or ah (51), because they dont have ports like tcp and udp.
so you would need to nat all traffic from one ip to another and this will cause ipsec to fail. you need to get the public address on the firewall interface, or get some more addresses.
Business Accounts
Answer for Membership
by: carlson777Posted on 2009-07-21 at 23:36:22ID: 24911976
Are you saying that the one statically assigned IP address is now used by the router's outside interface to talk with the ISP? Asking this because you said they only have one IP.