<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Public IP to internal over L2L and through a NAT? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/public-ip-to-internal-over-l2l-and-through-a-nat/m-p/1027565#M919560</link>
    <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got a tricky situation right now and need some additional brainpower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a PIX515E running 7.2.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a L2L VPN tunnel to another company where we have our servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, a server at the other company site needs a public IP and has to go through our own  PIX and over the L2L tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently we are NAT'ing all traffic to the other company over the L2L. This works good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our server has the IP: 10.1.1.5, and we are giving it a public ip (fake) 192.1.1.5 in my own PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How shall I do the static?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will it be : static (inside,outside) 192.1.1.5 10.1.1.5 netmask 255.255.255.255 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Considering that the our server 10.1.1.5 is really "outside" from my PIX point of view?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How shall I turn the traffic around and enter the L2L and get NAT'ed towards the server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I previously made it possible to VPN to our PIX and then be able to work against the servers with NAT'ing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I just had to add another NAT for (outside) and it worked. I've even tried adding another ACL line and permitting any traffic towards 10.1.1.5. Not working tho&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would really appreciate some help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:49:57 GMT</pubDate>
    <dc:creator>azore2007</dc:creator>
    <dc:date>2019-03-11T12:49:57Z</dc:date>
    <item>
      <title>Public IP to internal over L2L and through a NAT?</title>
      <link>https://community.cisco.com/t5/network-security/public-ip-to-internal-over-l2l-and-through-a-nat/m-p/1027565#M919560</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Got a tricky situation right now and need some additional brainpower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a PIX515E running 7.2.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a L2L VPN tunnel to another company where we have our servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This works good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, a server at the other company site needs a public IP and has to go through our own  PIX and over the L2L tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently we are NAT'ing all traffic to the other company over the L2L. This works good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our server has the IP: 10.1.1.5, and we are giving it a public ip (fake) 192.1.1.5 in my own PIX&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How shall I do the static?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will it be : static (inside,outside) 192.1.1.5 10.1.1.5 netmask 255.255.255.255 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Considering that the our server 10.1.1.5 is really "outside" from my PIX point of view?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How shall I turn the traffic around and enter the L2L and get NAT'ed towards the server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I previously made it possible to VPN to our PIX and then be able to work against the servers with NAT'ing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then I just had to add another NAT for (outside) and it worked. I've even tried adding another ACL line and permitting any traffic towards 10.1.1.5. Not working tho&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would really appreciate some help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/public-ip-to-internal-over-l2l-and-through-a-nat/m-p/1027565#M919560</guid>
      <dc:creator>azore2007</dc:creator>
      <dc:date>2019-03-11T12:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: Public IP to internal over L2L and through a NAT?</title>
      <link>https://community.cisco.com/t5/network-security/public-ip-to-internal-over-l2l-and-through-a-nat/m-p/1027566#M919566</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Go through this NAT and Access Lists (Cisco PIX 500 Series Security Appliances Configuration guide) for your configuration . It will help for the configuration.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://cisco.com/en/US/products/hw/vpndevc/ps2030/prod_configuration_examples_list.html" target="_blank"&gt;http://cisco.com/en/US/products/hw/vpndevc/ps2030/prod_configuration_examples_list.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 May 2008 13:40:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/public-ip-to-internal-over-l2l-and-through-a-nat/m-p/1027566#M919566</guid>
      <dc:creator>wong34539</dc:creator>
      <dc:date>2008-05-30T13:40:06Z</dc:date>
    </item>
  </channel>
</rss>

