<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Dinesh, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880467#M167302</link>
    <description>&lt;P&gt;Hi Dinesh,&lt;/P&gt;
&lt;P&gt;Thanks for your reply!&lt;BR /&gt;All configured, I'm waiting for other party to configure their end and start testing.&lt;BR /&gt;&lt;BR /&gt;May I ask where I can set the Renegotiation of Phase 2 in seconds?&lt;BR /&gt;&lt;BR /&gt;I've looked and can only find the Phase 1 as per below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;crypto ikev1 enable outside&lt;BR /&gt;crypto ikev1 policy 5&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption aes&lt;BR /&gt; hash sha&lt;BR /&gt; group 5&lt;BR /&gt; &lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;lifetime 86400&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 21 Mar 2016 11:34:44 GMT</pubDate>
    <dc:creator>haidar_alm</dc:creator>
    <dc:date>2016-03-21T11:34:44Z</dc:date>
    <item>
      <title>Site-to-Site VPN with Source NAT</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880465#M167300</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;I'm trying to use ASDM on ASA version 9.5(1) where I need to set up a site to site VPN with my local inside server to be NAT-ed to a different address in order to mitigate IP address Overlapping.&lt;BR /&gt;&lt;BR /&gt;I've seen a few examples using CLI, but I'm wondering what's the best way to do this using ASDM?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I'm aware that this is an overkill since there is no overlap of subnets. However, this is a requirement that I'm trying to work on.. &lt;BR /&gt;&lt;BR /&gt;Below are the steps and my thoughts:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;My local server for argument's sake is 1.1.1.1, remote server is 2.2.2.2&lt;BR /&gt;&lt;BR /&gt;When I go through the VPN setup, I enter peer IP, local and remote hosts, and I get to NAT Exempt..&lt;BR /&gt;&lt;BR /&gt;I keep this option of NAT Exempt unticked, finalize wizard.&lt;BR /&gt;&lt;BR /&gt;Then, create a Static NAT:&lt;/P&gt;
&lt;P&gt;Match Criteria: Original Packet&lt;/P&gt;
&lt;P&gt;Source: Inside&lt;BR /&gt;Destination: Outside&lt;BR /&gt;Source NAT Type: Static&lt;BR /&gt;Source Address: Local Server&lt;BR /&gt;Destination Address: Remote Server &lt;BR /&gt;Service: any&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Action: Translated Packet&lt;BR /&gt;Source NAT Type: Static&lt;BR /&gt;Source Address: In here I put the Mapped IP of 3.3.3.3&lt;BR /&gt;Destination Address: Original&lt;BR /&gt;&lt;BR /&gt;Enable Rule&lt;BR /&gt;Direction: Both&lt;BR /&gt;&lt;BR /&gt;Am I thinking along the right lines or am I way off the track here?&lt;BR /&gt;&lt;BR /&gt;Any suggestion would be helpful.&lt;BR /&gt;&lt;BR /&gt;Many thanks...&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:30:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880465#M167300</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2019-03-12T07:30:57Z</dc:date>
    </item>
    <item>
      <title>If you wish to accomplish the</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880466#M167301</link>
      <description>&lt;P&gt;If you wish to accomplish the IP 1.1.1.1 to be translated to 3.3.3.3 when you are communicating to 2.2.2.2, then this natting looks correct.&lt;BR /&gt;&lt;BR /&gt;Make sure the crypto access-list is defined from &amp;nbsp;3.3.3.3 to 2.2.2.2 , rather &amp;nbsp;1.1.1.1 to 2.2.2.2, as the source will be translated before sending the packet over the tunnel/.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Additionally, you can run packet-tracer to see the packet is traversing the ASA correctly.&lt;/P&gt;
&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;BR /&gt;&lt;BR /&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Sun, 20 Mar 2016 04:49:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880466#M167301</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-03-20T04:49:31Z</dc:date>
    </item>
    <item>
      <title>Hi Dinesh,</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880467#M167302</link>
      <description>&lt;P&gt;Hi Dinesh,&lt;/P&gt;
&lt;P&gt;Thanks for your reply!&lt;BR /&gt;All configured, I'm waiting for other party to configure their end and start testing.&lt;BR /&gt;&lt;BR /&gt;May I ask where I can set the Renegotiation of Phase 2 in seconds?&lt;BR /&gt;&lt;BR /&gt;I've looked and can only find the Phase 1 as per below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;crypto ikev1 enable outside&lt;BR /&gt;crypto ikev1 policy 5&lt;BR /&gt; authentication pre-share&lt;BR /&gt; encryption aes&lt;BR /&gt; hash sha&lt;BR /&gt; group 5&lt;BR /&gt; &lt;STRONG&gt;&lt;SPAN style="text-decoration: underline;"&gt;lifetime 86400&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Many thanks,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 11:34:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880467#M167302</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2016-03-21T11:34:44Z</dc:date>
    </item>
    <item>
      <title>Hi Haidar,</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880468#M167303</link>
      <description>&lt;P&gt;Hi Haidar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Here is the command to configure the Phase 2 lifetime:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;crypto ipsec security-association lifetime seconds 28800&lt;BR /&gt;crypto ipsec security-association lifetime kilobytes 4608000&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;
&lt;P&gt;https://supportforums.cisco.com/document/105381/basic-l2l-configuration-platform-independent-approach#Phase-2_Lifetime_Setting&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;On ASDM go to the Connection profile edit the connection and go to the advanced &amp;nbsp;tab and expand it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Click on the crypto map&amp;nbsp;entry tab and you would see the Security association lifetime.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;You can enter the desired values and this would change the PHASE-2 lifetime.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it answers your query.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 11:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880468#M167303</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-03-21T11:49:36Z</dc:date>
    </item>
    <item>
      <title>Ah, I saw that earlier but</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880469#M167304</link>
      <description>&lt;P&gt;Ah, I saw that earlier but wasn't sure if it was for phase 1 or 2.&lt;BR /&gt;&lt;BR /&gt;Will update post once testing is complete.. hopefully all will be good..&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank you for your help!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Mar 2016 12:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880469#M167304</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2016-03-21T12:13:52Z</dc:date>
    </item>
    <item>
      <title>Hi Dinesh,</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880470#M167305</link>
      <description>&lt;P&gt;Hi Dinesh,&lt;/P&gt;
&lt;P&gt;Worked like a treat.. many thanks for your help mate!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 09:14:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880470#M167305</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2016-03-23T09:14:15Z</dc:date>
    </item>
    <item>
      <title>Hi Aditya,</title>
      <link>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880471#M167306</link>
      <description>&lt;P&gt;Hi Aditya,&lt;/P&gt;
&lt;P&gt;All done and working, thanks for your assistance mate.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 09:14:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/site-to-site-vpn-with-source-nat/m-p/2880471#M167306</guid>
      <dc:creator>haidar_alm</dc:creator>
      <dc:date>2016-03-23T09:14:46Z</dc:date>
    </item>
  </channel>
</rss>

