Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations biv343 on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

nat 0 problemmm!

Status
Not open for further replies.

bladeka

IS-IT--Management
Sep 23, 2004
51
EG
Dear Friends

i need an answer to a simple question as fast as possible please ..
my manager wil kick me out !

i have :

my server ---->PIX506(peer)---->(VPN through Internet)--->NOrtel Firewall(peer) --->internal network

the internal network suppoesed to access my server on port 5000 ..
i have nat 0 on the nortel Firewall & nat 1 on the PIX ....
the VPN is up and everything is normally .. but my problem that this internal network is accessing everything on the my server .. am gone crazy .. i know that nat 0 translates the internal network as if it is inside my network .. but i have an access list that allow ay traffic that come from the internal network to acesss my server on port 5000 only & i applied it on the crypto map :(

am dieing out there !
 
guys i opened the case with cisco and i got 2 solutions

1- use the following command to let the crypto sec pass throught the access-list

no sysopt connection ip-sec

2-define the access list as interestig traffic of the crypto map


enjoy ...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top