Joesmail
asked on
Cisco PIX Site to Site VPN using NAT on internal addresses
Cisco PIX Site to Site VPN using NAT on internal addresses
I am setting up a VPN connection to a customer that uses Checkpoint Firewall.
They (the customer running Checkpoint) already have a VPN connection to another customer who uses our internal address (192.168.1.0).
I would like to setup our VPN like this:
Our internal address 192.168.1.0 255.255.255.0 address range ----------> NAT to 172.x.x.x over a VPN tunnel to their site.
We already have several VPN's on our firewall. So I will probably only need to setup a crypto map xx......
We are using a PIX515E.
Can someone supply me with the commands to accomplish this.
I am setting up a VPN connection to a customer that uses Checkpoint Firewall.
They (the customer running Checkpoint) already have a VPN connection to another customer who uses our internal address (192.168.1.0).
I would like to setup our VPN like this:
Our internal address 192.168.1.0 255.255.255.0 address range ----------> NAT to 172.x.x.x over a VPN tunnel to their site.
We already have several VPN's on our firewall. So I will probably only need to setup a crypto map xx......
We are using a PIX515E.
Can someone supply me with the commands to accomplish this.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
You are brillant!
Code works perfectly.
One other question and its not that important.
I can't use the PDM anymore because it is saying it dosen't support NAT using acl's. Only in MONITOR mode...
Is their any way around this, it dosen't matter if I have to use the command line from now on, just a pain for small tasks.
Cheers,
Code works perfectly.
One other question and its not that important.
I can't use the PDM anymore because it is saying it dosen't support NAT using acl's. Only in MONITOR mode...
Is their any way around this, it dosen't matter if I have to use the command line from now on, just a pain for small tasks.
Cheers,
You might have to upgrade the OS to 6.3(4) and PDM 3.02 to support this feature.
Glad it worked for you!
Glad it worked for you!
ASKER
I will give it ago as soon as my overseas customer gets back to me.