Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > PIX 6.3(5) NAT Headache

Reply
Thread Tools

PIX 6.3(5) NAT Headache

 
 
Darren
Guest
Posts: n/a
 
      04-24-2008
Due to some inflexibility on the part of a 3rd party I am faced with
adding NAT complexity to what was going to be a simple solution (public
to public VPN).

My network has a PIX pair running 6.3(5). There are several interfaces
and lots of NAT, Policy NAT etc. To keep thing simple the point of
interest are...

static (inside,outside) 62.X.X.1 172.16.1.1 netmask 255.255.255.255
static (inside,outside) 62.X.X.2 172.16.1.2 netmask 255.255.255.255

Originally my crypto-acl was going to use these 2 x public IP's. Now the
remote end is telling me that they will not do a public to public
connection and they insist that....

Their users will come from say 10.1.1.0/24 (on the outside) and will
target the above hosts 62.X.X.1 & .2 by the address 172.23.1.1 & 2
respectively.

So on my PIX I have to say, anything from a source address of
10.1.1.0/24 targeting a destination address of 172.23.1.1 & .2 NAT to
the real addresses of 172.16.1.1 & .2.

My second problem is I may have to modify the source address of the
traffic (10.1.1.0/24) as the main site I control uses various ranges in
10.0.0/8. With this in mind I take it I would need outside NAT.

Any help appreciated here.

I off to blow the dust off my PIX book now to see if I can find a good
example or two.

Regards

Darren
 
Reply With Quote
 
 
 
 
networkzman
Guest
Posts: n/a
 
      04-25-2008
Hello Darren,

we could achive this by adding a no nat access rule.
eg:

http://www.cisco.com/warp/public/110/38.html

Thanks

Darren wrote:
> Due to some inflexibility on the part of a 3rd party I am faced with
> adding NAT complexity to what was going to be a simple solution (public
> to public VPN).
>
> My network has a PIX pair running 6.3(5). There are several interfaces
> and lots of NAT, Policy NAT etc. To keep thing simple the point of
> interest are...
>
> static (inside,outside) 62.X.X.1 172.16.1.1 netmask 255.255.255.255
> static (inside,outside) 62.X.X.2 172.16.1.2 netmask 255.255.255.255
>
> Originally my crypto-acl was going to use these 2 x public IP's. Now the
> remote end is telling me that they will not do a public to public
> connection and they insist that....
>
> Their users will come from say 10.1.1.0/24 (on the outside) and will
> target the above hosts 62.X.X.1 & .2 by the address 172.23.1.1 & 2
> respectively.
>
> So on my PIX I have to say, anything from a source address of
> 10.1.1.0/24 targeting a destination address of 172.23.1.1 & .2 NAT to
> the real addresses of 172.16.1.1 & .2.
>
> My second problem is I may have to modify the source address of the
> traffic (10.1.1.0/24) as the main site I control uses various ranges in
> 10.0.0/8. With this in mind I take it I would need outside NAT.
>
> Any help appreciated here.
>
> I off to blow the dust off my PIX book now to see if I can find a good
> example or two.
>
> Regards
>
> Darren

 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
PIX - mixing "nat 0 access-list" with nat/global pools Matthew Melbourne Cisco 2 02-12-2005 03:17 PM
tftp to srvr behind pix: use nat or no-nat? Jose Cisco 3 10-24-2004 02:42 PM
PIX Policy NAT: order of NAT commands Oleg Tipisov Cisco 4 08-13-2004 07:13 PM
Pix-to-Pix VPN - BOTH BOXES BEHIND NAT!!! Michael Gorsuch Cisco 1 10-24-2003 09:35 AM
Re: PIX 501 configuration headache Shawn Westerhoff Cisco 0 10-14-2003 11:30 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57