Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Cisco 877 NAT & VPN

Status
Not open for further replies.

MinistryCork

Technical User
Oct 14, 2008
6
IE
All,
i have set up a NAT rule to an address which is only accessible over a vpn. The vpn is configured and working but the NAT rule doesnt seem to be. Am i missing something?

All feedback wlecome!
 
ip nat inside source static tcp 172.16.90.202 23 86.43.109.234 23 extendable

Is this what you're talking about?

Burt
 
That is the nat statement to allow lan traffioc out on the public ip its the other nat statement ip nat inside source static tcp 213.233.158.50 10.0.2.100 8001 extendable thats the problem. 10.0.2.100 is only reachabl.e over the VPN
 
But if you VPN in, why would you want to NAT it to a public IP? Unless you mean that without the VPN it needs a NAT, and therefore is NOT reachable once vpn'd in...IPSEC and NAT do not play well together...

Burt
 
The VPN's are both at site A. one to site b and one to site c. 10.0.2.0/24 is accessable over the vpn to site B and 213.233.159.0/24 is accessbale over the von to site C. Site B has an application running on it whih is hardcoded with an address which points to 213.233.158.50. 10.0.2.100 also has the same service running on it as the .50 address so what we want to achieve is to NAT the traffic setined for 158.50 to 2.100 so the application will work with the hardcoded address which cannoyt be changed.

I hope this makes it a liitle clearer.

Regards,
Tony.
 
Have IT!
ip nat outside source static 10.0.2.102 213.233.158.50

HAS DONE THE TRICK!

Thanks for the help Burt, it put me on the right track
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top