<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX - NAT- 1750? Can it Be Done. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-nat-1750-can-it-be-done/m-p/8414#M693478</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that should work fine.  Not sure what your concerns are with the 1750 in the topology.  Is it just routing for your LAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 15 Jun 2001 20:12:17 GMT</pubDate>
    <dc:creator>bstremp</dc:creator>
    <dc:date>2001-06-15T20:12:17Z</dc:date>
    <item>
      <title>PIX - NAT- 1750? Can it Be Done.</title>
      <link>https://community.cisco.com/t5/network-security/pix-nat-1750-can-it-be-done/m-p/8413#M693453</link>
      <description>&lt;P&gt;Hello Forum,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I place a 1750 Behind a PIX 520 and have the PIX NAT a Public IP Address on the Outside Interface (Internet) to a Private IP Address on the pix/inf2 and have a IPSec Tunnel come up and pass traffic? My guess is that it won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If Not, what would be the recommended design?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jerry Roy&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:jroy@axcelerant.com" target="_blank"&gt;jroy@axcelerant.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-nat-1750-can-it-be-done/m-p/8413#M693453</guid>
      <dc:creator>jerry.roy</dc:creator>
      <dc:date>2020-02-21T05:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: PIX - NAT- 1750? Can it Be Done.</title>
      <link>https://community.cisco.com/t5/network-security/pix-nat-1750-can-it-be-done/m-p/8414#M693478</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that should work fine.  Not sure what your concerns are with the 1750 in the topology.  Is it just routing for your LAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Jun 2001 20:12:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-nat-1750-can-it-be-done/m-p/8414#M693478</guid>
      <dc:creator>bstremp</dc:creator>
      <dc:date>2001-06-15T20:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX - NAT- 1750? Can it Be Done.</title>
      <link>https://community.cisco.com/t5/network-security/pix-nat-1750-can-it-be-done/m-p/8415#M693505</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Answer to your question depends on where the crypto endpoint is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the 1750 is an endpoint of the crypto tunnel (and the PIX doing NAT is just firewalling)&lt;/P&gt;&lt;P&gt;then IPSec in certain fashions will work.    &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IKE is UDP 500 and is NAT-friendly - no problem.&lt;/P&gt;&lt;P&gt;AH is IP protocol 51 - and authenticates most of the IP header.  This is a problem.  Not NAT&lt;/P&gt;&lt;P&gt;friendly&lt;/P&gt;&lt;P&gt;ESP (protocol 50) provides both authentication and encryption functions.  In tunnel mode, you'll&lt;/P&gt;&lt;P&gt;have no problems either (the IP address fields in the header are considered mutable)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the PIX is the endpoint, then there is no problem with anything because the PIX order of&lt;/P&gt;&lt;P&gt;operations is such that NAT occurs before IPSec on the egress interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Rakesh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2001 06:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-nat-1750-can-it-be-done/m-p/8415#M693505</guid>
      <dc:creator>rbharania</dc:creator>
      <dc:date>2001-07-24T06:43:24Z</dc:date>
    </item>
  </channel>
</rss>

