I've done many VPN setups using the ASDM Site-to-Site Wizard in the past. But, a company we are trying to connect with now is requiring us to NAT our internal server IP to a public address they have provided. I have searched to no avail on this and tried many configurations. A walkthrough of the correct setup using the ASDM GUI would be appreciated. I know nothing about using CLI and I would be scared I would mess something up and cause more problems. It would be helpful for what to put into the VPN Wizard and then how to setup the NAT'ing. Static NAT or Policy NAT? Do I de-select NAT Exemption on the VPN Wizard screen? These are the issues I'm having with this. If I haven't explained very well, please let me know of any additional info you may need to help me. Thank You in advance.
My parameters: (fake addresses)
Peer IP: 173.243.xxx.xxx
Internal Server IP: 172.16.2.153 (needs to be NATed to 161.250.141.249 for traffic on TCP port 2004)
Company I'm connecting to:
Peer IP: 161.250.81.xxx
Encryption Domain: 162.250.140.1
Cisco order of operations is for NAT to occur before crypto, so the traffic will be NAT'd, then encrypted. For the encryption to work, the interesting traffic has to match the public IP of the server.