Cisco ASA5505 VPN Tunnel Using Nat

Cisco ASA5505 VPN Tunnel Using Nat

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Cisco ASA5505 VPN Tunnel Using Nat Newbie72 08-17-2007
Posted by Newbie72 on August 17, 2007, 9:34 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I have been asked to setup a site-site VPN tunnel using IPSEC.
Building the tunnel is not a issue for me. However, the folks at the
remote site are requiring that we provide a public ip address for our
local host. which they will be connecting to. I have searched the
cisco.com site and have not found a easy explained solution. The
remote site wants a configuration simular to below

Remote Site VPN End Point: 1.1.1.1
Host Ip Address at remote site 2.2.2.1 and 2.2.2.2

Our site
VPN End Point: 3.3.3.3
Local Host which will be tunneling traffic: They are requiring this to
be a public ip. Currently we use RFC-1918 addresses which means we
will have to translate a public address to our private host addresses.

Can I simply setup a static NAT statement which translates the public
address to our private addresss as we are only using one host on our
side?Then do I set "match address" to the public IP?

Thanks,
Steve J


Posted by Newbie72 on August 20, 2007, 12:47 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
wrote:
> I have been asked to setup a site-site VPN tunnel using IPSEC.
> Building the tunnel is not a issue for me. However, the folks at the
> remote site are requiring that we provide a public ip address for our
> local host. which they will be connecting to. I have searched the
> cisco.com site and have not found a easy explained solution. The
> remote site wants a configuration simular to below
>
> Remote Site VPN End Point: 1.1.1.1
> Host Ip Address at remote site 2.2.2.1 and 2.2.2.2
>
> Our site
> VPN End Point: 3.3.3.3
> Local Host which will be tunneling traffic: They are requiring this to
> be a public ip. Currently we use RFC-1918 addresses which means we
> will have to translate a public address to our private host addresses.
>
> Can I simply setup a static NAT statement which translates the public
> address to our private addresss as we are only using one host on our
> side?Then do I set "match address" to the public IP?
>
> Thanks,
> Steve J

Anbody got any suggestions?


Posted by Scott Stokes on November 4, 2007, 9:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Newbie72 wrote:
> wrote:
>> I have been asked to setup a site-site VPN tunnel using IPSEC.
>> Building the tunnel is not a issue for me. However, the folks at the
>> remote site are requiring that we provide a public ip address for our
>> local host. which they will be connecting to. I have searched the
>> cisco.com site and have not found a easy explained solution. The
>> remote site wants a configuration simular to below
>>
>> Remote Site VPN End Point: 1.1.1.1
>> Host Ip Address at remote site 2.2.2.1 and 2.2.2.2
>>
>> Our site
>> VPN End Point: 3.3.3.3
>> Local Host which will be tunneling traffic: They are requiring this to
>> be a public ip. Currently we use RFC-1918 addresses which means we
>> will have to translate a public address to our private host addresses.
>>
>> Can I simply setup a static NAT statement which translates the public
>> address to our private addresss as we are only using one host on our
>> side?Then do I set "match address" to the public IP?
>>
>> Thanks,
>> Steve J
>
> Anbody got any suggestions?
>

This is a lot easier than most people think. Just nat the inside to an
external IP.

static (inside,outside) 4.4.4.4 3.3.3.3 netmask 255.255.255.255

And then when you configure the ACLs for the VPN use the 4.4.4.4 as the
host on your side. And do not configure a NoNat ACL.

That's it.

Scott


Posted by Newbie72 on November 5, 2007, 1:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
> Newbie72 wrote:
> > wrote:
> >> I have been asked to setup a site-site VPN tunnel using IPSEC.
> >> Building the tunnel is not a issue for me. However, the folks at the
> >> remote site are requiring that we provide a public ip address for our
> >> local host. which they will be connecting to. I have searched the
> >> cisco.com site and have not found a easy explained solution. The
> >> remote site wants a configuration simular to below
>
> >> Remote Site VPN End Point: 1.1.1.1
> >> Host Ip Address at remote site 2.2.2.1 and 2.2.2.2
>
> >> Our site
> >> VPN End Point: 3.3.3.3
> >> Local Host which will be tunneling traffic: They are requiring this to
> >> be a public ip. Currently we use RFC-1918 addresses which means we
> >> will have to translate a public address to our private host addresses.
>
> >> Can I simply setup a static NAT statement which translates the public
> >> address to our private addresss as we are only using one host on our
> >> side?Then do I set "match address" to the public IP?
>
> >> Thanks,
> >> Steve J
>
> > Anbody got any suggestions?
>
> This is a lot easier than most people think. Just nat the inside to an
> external IP.
>
> static (inside,outside) 4.4.4.4 3.3.3.3 netmask 255.255.255.255
>
> And then when you configure the ACLs for the VPN use the 4.4.4.4 as the
> host on your side. And do not configure a NoNat ACL.
>
> That's it.
>
> Scott- Hide quoted text -
>
> - Show quoted text -

I should have went back and closed this thread. you are right though.
It ended up being alot easier than I thought.

I ran out time and threw caution to the wind a week or 2 ago and did
just as you suggested and it now works flawlessly. Thanks for the
reply.


Similar ThreadsPosted
SSH Cisco ASA5505 March 14, 2008, 1:07 pm
Cisco PIX 7.0.1 to Watchguard V60 VPN Tunnel September 15, 2005, 3:06 pm
[flash taturial]Configure Cisco GRE tunnel August 3, 2007, 11:29 pm
VPN vs. VPN Tunnel September 29, 2006, 7:20 pm
VPN tunnel through GPRS August 25, 2005, 10:11 am
Netscreen 204 to 5XT tunnel May 2, 2006, 3:28 pm
netscreen vpn tunnel January 8, 2008, 9:31 am
SSH tunnel over SQUID October 15, 2008, 8:30 pm
Reverse HTTPS Tunnel??? February 8, 2005, 7:43 am
IPSEC tunnel in China April 12, 2005, 11:22 pm

The site map in XML format XML site map

Contact Us | Privacy Policy