Solved

Private to Private NAT over VPN

Posted on 2008-10-10
4
511 Views
Last Modified: 2012-05-05
I have a vendor requesting to form a VPN where all traffic from me over the VPN NATs to a single private address.  How do I have a NAT statement to map all inside addresses to a single private network address only over the VPN and for the VPN local network will I use the NATed address or still the local network address.  I have a 192.168 network and they are wanting me to NAT to 10.129 address for use of the VPN.   So they are wanting all network activity to appear to come from a single 10.129 address.
0
Comment
Question by:dublincityschools
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 250 total points
ID: 22696078
Actually, it's pretty easy.
create a conditional nat acl, ie.
 access-list conditional_nat permit ip 192.168.x.x 255.255.255.0 <their network> 255.255.255.0

apply conditional_nat
 global (outside) 12 10.129.x.x
 nat (inside) 12 access-list conditional_nat

Now, use the natted IP in the crypto match acl
 access-list outside_cryptomap_12 pemit ip host 10.129.x.x <their network> 255.255.255.0

Apply this crypto map acl to the crypto map peer.
Done.
0
 

Author Comment

by:dublincityschools
ID: 22706375
I figured that out this weekend but I am glad to get confirmation from someone with more knowledge.  We send all traffic to them as 10.129.~.29 but they also want all traffic sent back to us as 10.129.~.30.  Will I have to do any configuration on my end for this or just expand the network subnet originally entered in the access-list?

They also want to set it up where every printer they print to is static NAT to a 10.129 address.  I know I will have to put the static nat entry in and also expand the access-list subnet.  Is there anything else?
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 22708712
Check out this guide
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00808c9950.shtml
They should nat their end, but if they wont, You might have to do something like
nat (outside) 10 <their subnet>
 global (inside) 10 10.129.x.30

0
 

Author Comment

by:dublincityschools
ID: 22711377
That is the link I found this weekend that helped me.  Thank you for your help.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Palo Alto Networks: Packet Trace Simulator? 2 119
Internet Connection -- PING testing ? 1 62
ASA 5505 latency problem 8 64
TZ400 2 28
OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question