01-04-2024 04:21 AM
Hello Community
I was create a site to site VPN but it failed to come up for unknown reason. I kindly ask for help.
I have two site. One is Site-A and Second is Site-B.
At Site A I have NAT Host PC 10.1.1.10 to NAT 200.1.1.25 when I tried to initiate icmp from Site B 10.2.2.10 using 200.1.1.25 , I'm getting host not reachable. See attached my running configuration for help.
*10.2.2.254 icmp_seq=1069 ttl=255 time=0.391 ms (ICMP type:3, code:1, Destination host unreachable)
*10.2.2.254 icmp_seq=1070 ttl=255 time=0.617 ms (ICMP type:3, code:1, Destination host unreachable)
*10.2.2.254 icmp_seq=1071 ttl=255 time=0.696 ms (ICMP type:3, code:1, Destination host unreachable)
*10.2.2.254 icmp_seq=1072 ttl=255 time=0.538 ms (ICMP type:3, code:1, Destination host unreachable)
01-04-2024 06:13 AM
Friend
you need Loopback and enable NAT to make it work.
the NAT before forward traffic via IPsec is not support in IOS unless we use Lo, where we direct the traffic to Lo (NATing there) then pass through tunnel
MHM
01-04-2024 12:38 PM
01-04-2024 10:45 PM
can I know the router of both VPN tunnel head ?
are it IOS or IOS XE ?
MHM
01-10-2024 10:54 PM
01-11-2024 06:35 AM
there is no attachment
but I will make it simple to you
LAN1-Router1-Internet-Router2-LAN2
NOW we need to NATing LAN1 to other subnet before pass it through the IPSec VPN
we config LO in R1
we config PBR that direct traffic from LAN1 to LAN2 to LO
we config LO with ip nat enable
we config LAN1 interface with ip nat enable
we config NATing
the traffic now from LAN1 go to LO then it NATing then forward through the tunnel
MHM
01-11-2024 11:32 AM
01-11-2024 11:43 AM
in siteA router
can you add
ip nat enable
under any Loopback interface ?
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide