<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic it was resolved by add a NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826831#M173786</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;it was resolved by add a NAT Exemption:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;nat (inside,outside) source static NETWORK_OBJ_local NETWORK_OBJ_local destination static NETWORK_OBJ_VPNPool NETWORK_OBJ_VPNPool&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 24 Dec 2015 06:26:43 GMT</pubDate>
    <dc:creator>abdelkarim.yousef</dc:creator>
    <dc:date>2015-12-24T06:26:43Z</dc:date>
    <item>
      <title>IPSec VPN Tunnel</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826828#M173782</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have established an IPSec VPN Connection, and created access list to allow traffic to some internal resources through VPN.&lt;/P&gt;
&lt;P&gt;But when I try to allow internet access to an internal resource by using NAT, the VPN to this resource be disconnected.&lt;/P&gt;
&lt;P&gt;So I can enable either VPN or internet to the local resource.&lt;/P&gt;
&lt;P&gt;I need to enable both. Any help&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826828#M173782</guid>
      <dc:creator>abdelkarim.yousef</dc:creator>
      <dc:date>2019-03-12T07:04:23Z</dc:date>
    </item>
    <item>
      <title>When you have a VPN with some</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826829#M173784</link>
      <description>&lt;P&gt;When you have a VPN with some or all of the resources also having a NAT policy, you need to exempt the traffic to / from the remote VPN networks from NAT as you want to keep the true IP address for the traffic flowing through the VPN.&lt;/P&gt;
&lt;P&gt;For example:&amp;nbsp;https://supportforums.cisco.com/document/44566/asa-83-nat-exemption-example-basic-l2l-vpn-and-basic-ra-vpn&lt;/P&gt;
&lt;P&gt;What hardware and software versions are you using? We can provide some more specific sample configurations if you provide that information.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Dec 2015 18:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826829#M173784</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-23T18:43:29Z</dc:date>
    </item>
    <item>
      <title>ASA 5520</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826830#M173785</link>
      <description>&lt;P&gt;ASA 5520&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 8.3(1)&lt;/P&gt;
&lt;P&gt;internal network 192.168.0.0/24&lt;/P&gt;
&lt;P&gt;VPN Client with split tunnel&lt;/P&gt;
&lt;P&gt;access-list VPN line 1 extended permit tcp any host 192.168.0.216 eq 90&lt;/P&gt;
&lt;P&gt;So when a user opens a vpn connection, he can reach host 192.168.0.216 on port 90.&lt;/P&gt;
&lt;P&gt;but when we add a nat rule to allow internet access for host 192.168.0.216, the vpn connection to this host be unreachable.&lt;/P&gt;
&lt;P&gt;object network host1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.0.216&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside2,outside) dynamic interface&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 05:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826830#M173785</guid>
      <dc:creator>abdelkarim.yousef</dc:creator>
      <dc:date>2015-12-24T05:47:17Z</dc:date>
    </item>
    <item>
      <title>it was resolved by add a NAT</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826831#M173786</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;it was resolved by add a NAT Exemption:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;nat (inside,outside) source static NETWORK_OBJ_local NETWORK_OBJ_local destination static NETWORK_OBJ_VPNPool NETWORK_OBJ_VPNPool&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 06:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826831#M173786</guid>
      <dc:creator>abdelkarim.yousef</dc:creator>
      <dc:date>2015-12-24T06:26:43Z</dc:date>
    </item>
    <item>
      <title>Great. Please mark your</title>
      <link>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826832#M173787</link>
      <description>&lt;P&gt;Great. Please mark your question as answered if it has been.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Dec 2015 13:59:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ipsec-vpn-tunnel/m-p/2826832#M173787</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-12-24T13:59:03Z</dc:date>
    </item>
  </channel>
</rss>

