Link to home
Start Free TrialLog in
Avatar of 1ktw08
1ktw08

asked on

how to create vpn between 2 firewalls, when I have in the middle, a Cisco 837 with nat????

Hi there:

I want to create a IPSec VPN between two PIX ver 6.3, but in the middle I have a cisco 831 ADSL router just with 1 Homologated IP.

I had implemented NAT overload on the router.

I think we need to configure NAT-T, but the question here is how can be this configuration implemented???

Please i you can help me.

Regards.
NEW-IPSec-scenario.JPG
Avatar of brasslan
brasslan

That can be done.  When the VPN packets come in and hit the outside of the DSL router, then you need to port forward (or static nat) those packets to the PIX on the inside.  With NAT traversal turned on for the VPN at the endpoints, then it should work.
Avatar of 1ktw08

ASKER

Ok. Now, applying port forwarding on router ADSL, Remote Office can not access Internet (It suppose that I need to access Internet not using Tunnel, but directly from the router.

This scenario can be implemented too???

Where do I need to activate NAT-T, on bot PIX devices, or on the router????
Hi,

You need to enable NAT traversal on both endpoints as brasslan said: I think the is "isakmp nat-traversal".

Hope this helps
ASKER CERTIFIED SOLUTION
Avatar of 1ktw08
1ktw08

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of 1ktw08

ASKER

Any idea about this question???'

Regards