PIX VPN and NAT pb with Cisco 3000 concentrator

Discussion started by filip, Nov 19, 2003.

  1. filip

    filip Guest


    here is the pb :
    inside server ( -> pix inside -> pix outside (IP public)
    <-------------> cisco 3000 concentrator (ip public) -> remote

    the vpn is established between pix outside and VPNconcentrator
    this part is ok

    Now, my inside server should connect to remote host. But The remote host
    only accepts connections from one IP address :
    I have to Nat my inside server address ( to in the

    here are the commands I've entered :

    access-list 101 permit ip
    static (inside,outside) netmask 0
    crypto ipsec transform-set myset esp-3des esp-sha-hmac
    crypto map vpn 10 ipsec-isakmp
    crypto map vpn 10 match address 101
    crypto map vpn 10 set peer IPPublicVPNConcentrator
    crypto map vpn 10 set transform-set myset
    crypto map vpn interface outside
    isakmp enable outside
    isakmp key xxxxxxx address IPPublicVPNConcentrator netmask
    isakmp identity address
    isakmp policy 1 authentication pre-share
    isakmp policy 1 encryption 3des
    isakmp policy 1 hash sha
    isakmp policy 1 group 2
    isakmp policy 1 lifetime 48000

    But in the logs, I see that the nat translation doesn't work.
    the inside server is still trying to connect with his ip address
    ( and not with the natted address (
    LOGS :
    IPSEC(key_engine): request timer fired: count = 1,
    (identity) local= PixOutside, remote= IPPubVPNConcentrator,
    local_proxy= (type=4),
    remote_proxy= (type=1)

    The local proxy should be

    Where is the pb with this NAT ?

    filip, Nov 19, 2003
  2. filip

    Gav Reid Guest

    Believe NAT is completed before ACL is checked (can be corrected here)
    access-list 101 permit ip

    Dependent on your other NAT settings the following will work:
    This states users on the outside interface of the PIX, connect to and then the PIX redirects this to the internal interface on

    nat (inside) 1 0 0
    global (outside) 1
    Gav Reid, Nov 19, 2003
  3. filip

    filip Guest

    it worked,

    thank you

    filip, Nov 20, 2003
