Advertisement

01.23.2008 at 12:22PM PST, ID: 23105689
[x]
Attachment Details

Cisco Router and IPSEC Tunnel Configuration - NAT Issues

Asked by MainStaySolutions in Miscellaneous Networking, Network Routers, IPSec Security Protocol

Tags:

I have a Cisco 2821 router under my control that Im connecting to another Cisco router that is not under my control.  Im attempting to setup an IPSEC tunnel between the two routers working with the IT Engineer of the remote router.  The tunnel works fine except that I need to route a single IP to the remote end and the problem is it already in use on the remote network.  That IP Address is 10.30.1.7.  The remote IT Engineer has asked me to NAT that IP address on my end to 10.199.1.7 so that he can route traffic back to me.  I have setup many IPSEC tunnels but I have never NAT'ed the traffic going over the tunnel.  Any help would be much apprciated.  Below is the config of my router that deals with the tunnel.

crypto isakmp policy 1
 encr 3des
 hash md5
 authentication pre-share
 group 2
 lifetime 3600
crypto isakmp key test address 66..x.x.x

crypto map CiscoTunnel 1 ipsec-isakmp
 set peer 66.x.x.x
 set security-association lifetime kilobytes 4099445
 set transform-set ESP-3DES-md5
 match address 105

ip nat inside source route-map SDM_RMAP_1 interface Serial0/0/0:0 overload

access-list 101 deny   ip host 10.30.1.7 host 172..x.x.x
access-list 101 permit ip any any
access-list 101 permit icmp any any
access-list 105 permit ip host 10.30.1.7 host 172..x.x.x
access-list 105 deny   ip any any
access-list 105 permit icmp any any

route-map SDM_RMAP_1 permit 1
 match ip address 101



Start Free Trial
[+][-]01.23.2008 at 06:21PM PST, ID: 20730076

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]01.23.2008 at 07:28PM PST, ID: 20730328

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]01.24.2008 at 05:36AM PST, ID: 20732796

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]01.24.2008 at 05:58AM PST, ID: 20732974

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]01.24.2008 at 06:07AM PST, ID: 20733041

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]01.24.2008 at 06:13AM PST, ID: 20733095

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]01.24.2008 at 06:57AM PST, ID: 20733515

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]01.24.2008 at 07:34AM PST, ID: 20733899

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]01.24.2008 at 07:44AM PST, ID: 20734005

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]01.28.2008 at 05:03PM PST, ID: 20764558

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]01.28.2008 at 05:25PM PST, ID: 20764656

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]01.29.2008 at 05:43PM PST, ID: 20774006

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]01.29.2008 at 06:38PM PST, ID: 20774218

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]01.30.2008 at 04:51AM PST, ID: 20776558

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Miscellaneous Networking, Network Routers, IPSec Security Protocol
Tags: Cisco Router Configuration for IPSEC Tunnel
Sign Up Now!
Solution Provided By: stuknhawaii
Participating Experts: 1
Solution Grade: B
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628