[c-nsp] PIX: NAT inside a VPN?

Wolfgang Roth Wolfgang.Roth at brave.de
Tue Nov 22 04:47:43 EST 2005


Dear Garry,

> Is it possible to do a NAT on a PIX (7.0.x) inside a VPN? That is,
> remote network sets up a VPN to local Pix, but instead of using regular
> internal IPs, a NATted IP is used (in order to later possibly switch to
> a different server). Also, if, can an arbitrary IP be used?

it is possible with 6.3(X), but a little bit tricky. We use it here. It 
should work with 7.0(X) also.

You may use 'static (int1,int2) 1.2.3.4 access-list list-name 0 0' 
statements to implement this.

Best regards,


Wolfgang Roth


____________________________________________________________

Wolfgang Roth
Home of the Brave
Internet Technology Based Solutions GmbH
Telefon +49 (0) 621 16672-0
Telefax +49 (0) 621 16672-22
eMail Wolfgang.Roth at brave.de
____________________________________________________________


More information about the cisco-nsp mailing list