cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
311
Views
0
Helpful
1
Replies

L2L with single address

hamadriaz1
Level 1
Level 1

I know this has been asked a million times on the internet and for the life of me i can't figure out what seems to be happening here.


I have multiple networks on an ASA and we are now requested to setup a site to site with a vendor. In my past experience, i have always done site to site with NO NAT however the vendor requires us to pass all traffic from our inside networks (overlapping) to NAT address of single host 192.168.148.x


Everytime i am adding static (inside,outside) 192.168.140.x access-list policy-nat

I keep getting global address overlaps mask. Here is more details of what i am looking for:


Inside range: 192.168.0.x / 24, 10.100.0.x/22

Destination host: 10.5.225.x

Provider requested NAT: 192.168.148.x


Here is the config i have on my end, any help would be appreciated:


access-list VPN-TO-VENDOR extended permit ip host 192.168.148.x host 10.5.225.x

access-list policynat extended permit ip 192.168.0.0 255.255.255.0 host 10.5.225.x

Phase 2 is completed however no traffic is passing. When checking the ACL's there is no hit count either. I have tried to use static (inside,outside) 192.168.148.x access-list policynat and i keep getting global address overlaps mask. I am stuck any help would be appreciated.

1 Reply 1

Hi Hamad,

Please include the packet-tracer output.

packet-tracer input inside icmp 192.168.1.50 8 0 10.5.225.10 detail

Thanks.

Portu.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card