06-19-2024 12:52 PM
I am not sure if this is possible, but I can't get it to work.
We recently setup an IPSEC/VTI VPN with 'vendor A'. That tunnel and VTI interface are up. Routes are being exchanged via BGP. The VPN was setup on a Cisco ASA. The ASA has 2 VPN's to 'vendor A' (in the AWS cloud).
The vendor source network is 10.223.4.0/24. My infrastructure is simply a conduit between Vendor A and Vendor B.
Vendor B has an IP address that Vendor A needs to connect to at 172.16.31.82.
However, 172.16.31.82 conflicts with Vendor A's network.
Vendor A's traffic is incoming on a tunnel interface and outgoing traffic routes to inside interface.
I was trying to NAT 172.16.31.82 to 172.16.255.254 and advertise 172.16.255.254 to vendor A. When they come across the VPN attempting to connect to 172.16.255.254, the ASA NAT's it to 172.16.31.82. However, I can't apply NAT commands to a VTI Interface. Also, I only want the NAT to be applied to vendor A. I cant have anything else on my network hit that NAT rule.
Is this possible?
06-19-2024 12:58 PM
Can you share simple draw
Thanks
MHM
06-19-2024 01:19 PM
@MattMH you cannot apply a NAT to a tunnel nameif, you'd have to use. "any" in the NAT rule instead.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide