cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
801
Views
0
Helpful
1
Replies

PIX to 3005 through PIX with NAT

volyashevsky
Level 1
Level 1

Hello,

I am trying to establish a LAN to LAN tunnel between 501 and 3005 as a following:

501--Cable--520withNAT--3005onDMZ

Is this scenario possible? What things are different from regular or IOS LAN to LAN? Is 501 capable supporting this design?

What to look out for on 520?

Thank you for the help.

1 Reply 1

nohare
Level 1
Level 1

I've just recently set up this exact scenario at a customer site and it works fine.

.

You must make sure that the IPSEC protocols are allowed through the firewall to the NAT address you have used for your VPN 3005 (typically ESP and UDP/500 for ISAKMP)

.

The 501 should use the NAT address for its VPN gateway/peer.

.

Tried and tested and works fine.

Review Cisco Networking for a $25 gift card