itneedshelp
asked on
VPN and one to one NAT
I do tech work for small businesses and I barley dabble in VPN connections. I'm using a cisco VPN firewall. This one site I have a VPN tunnel is live, but for what ever reason when I use one to one NAT the device on that IP loses internet connection.
I need the one to one NAT for them to be able to ping the device. Any advice as to what I can do to avoid losing internet on this device? Is there another way? Remember I'm bit of a noobie when it comes to this stuff.
Thanks in advance.
I need the one to one NAT for them to be able to ping the device. Any advice as to what I can do to avoid losing internet on this device? Is there another way? Remember I'm bit of a noobie when it comes to this stuff.
Thanks in advance.
ASKER
It's site to site. The VPN tunnel is live and working. I just need them to be able to access this one device on the network. It'll work with DMZ host pointing to that address so I know it's the firewall blocking.
The our internal IP, for the device, is 10.1.100.250 and the site subnet is 10.1.10.X.
The our internal IP, for the device, is 10.1.100.250 and the site subnet is 10.1.10.X.
It'll work with DMZ host pointing to that address so I know it's the firewall blocking. <-- I do not try VPN through DMZ - just straight IP address and make sure firewall accommodates.
Did you try NAT Traversal?
Did you try NAT Traversal?
ASKER
I'm not sure this CISCO VPN firewall has a nat traversal setting.
I'm firmilar with it on a sonicwall, but I don't see it as an option on this firewall.
I'm firmilar with it on a sonicwall, but I don't see it as an option on this firewall.
ASKER
I have a CISCO RV120W VPN firewall.
ASKER
Looking at other CISCO firewalls I see the NAT Traversal setting in the VPN setup screen but it is not there in this model.
Try on the one where you have NAT Traversal and see if that works.
ASKER
Sorry I was referring to another site. This site only has the CISCO.
Try setting NAT Traversal at the other site.
ASKER
I do not have control for the other site. They're a separate company.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Thank you and I was happy to help.
Is this site to site or client to site?
Did you try NAT Transversal On and Off (both ways)