VPN between two networks with same IP ranges?

I have two networks with the same private IP range ( behind PIX firewalls.
The PIX firewalls have IPSec VPN tunnels connecting them.
Changing the IP range is not possible (due to some political limitations).
Is it possible for these two networks to talk?

I'm imagining some sort of NAT function before the VPN tunnel (or before the PIX) to convert one network range from to and then changing the VPN ACLs to look for on the changed side.
LVL 20
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Yes NAT should definitely resolve your problem definitely.
If any assistance required plz provide more details as in the whole network needs to be mapped thats many to 1(outgoing public ip; also use PAT in that case) or is 1 to 1 mapping required.

RPPreacherAuthor Commented:
Would I be able to do the NAT on the PIX (FOS 7.2.2) or would the NAT need to take place prior to the PIX outside interface?
I have never worked on PIX but i dont see any problem in PIX support for NAT.
You can use the following link as of now,

Will get back with more specific info soon..
Following link should help as well in configuring NAT on PIX,
Looks like a very good doc.

If you are looking for a VPN tunnel NATing using PIX then following link should help you,

Let me know.

Experts Exchange Solution brought to you by ConnectWise

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial


Follow the link and it is about overlap between PIX and 3000 Concentrator. Just looking at One PIX's configuration would be enough for you to figure out on the other side since I know you know :-)

So basically we nat the whole network to another network range on PIX itself and terminate the tunnel on the translated address.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.