Advertisement

06.30.2008 at 01:08PM PDT, ID: 23528186
[x]
Attachment Details

Cisco IOS VPN Same Interface NAT Routing

Asked by cisco_ in IPSec Security Protocol, Network Routers, Network Design & Methodology

Tags: Cisco, Cisco, 2621, IOS Crypto 12.3

Hi guys,

Hopefully this is an easy but I've been stumped for the last 2 months or so. With regards to an ASA/PIX, you can achieve this easily by the same interface traffic permit rule. I do not know how to enable this with a router and my configurations may be all wrong too! I will attempt to explain the situation.


Internal Network - 192.168.1.0/24
Cisco Fa0/0 - 192.168.1.1 (Internal Network's Default Gateway)
Cisco Fa0/1 - No IP add (PPPoE Client set up on this)
Cisco Dialer1 - 123.45.67.89/32 (Auto-negotiated)
Loopback100 - 192.168.50.1/24
VPN Users - 192.168.50.0/24


InternalNetwork-----Cisco2621-----ISP/InternetCloud-----RemoteVPN/Roadwarrior


My VPN access is fine and all that. I can ping the internal network and access the resources fine. What is bothering me is I cannot route traffic back out to the internet through the Cisco2621's NAT from my VPN Remote clients. I'm pretty sure there is a solution to this besides setting up a ISA proxy or Squid or Socks of any sort. Is there a resolution with the Cisco router itself? Please advise! Thanks in advance!!

Regards,
Cisco Dude in Need of Major Help


p/s Hope the "diagram" below helps. If you need to clarify anything don't hesitate to ask me I will be more than happy to explain myself.
202.202.202.201===VPNTUNNEL====CISCO2621===============NAT===========GOOGLE.COM
VPNUser / 192.168.50.2                      Cisco2621/123.45.67.89Start Free Trial
[+][-]07.01.2008 at 05:15AM PDT, ID: 21906829

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]07.01.2008 at 05:34AM PDT, ID: 21907045

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: IPSec Security Protocol, Network Routers, Network Design & Methodology
Tags: Cisco, Cisco, 2621, IOS Crypto 12.3
Sign Up Now!
Solution Provided By: lrmoore
Participating Experts: 1
Solution Grade: A
 
 
[+][-]07.03.2008 at 12:47AM PDT, ID: 21923456

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]07.03.2008 at 12:51AM PDT, ID: 21923477

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628