12-14-2012 04:54 AM - edited 03-11-2019 05:37 PM
Hi,
I am trying to conect two overlaping IP address sites ( see attached diagram). Site A LAN address will dynamic NAT to 10.1.1.0/24 at ASA5520.All the users from site A need to get services from site B ( DHCP, DNS, Mailbox,Print Servers, AD loggin etc). All the connections will be initiating from site A to B.
My question is
1-will all these services will run over NATed address.( dynamic) or I have to change to static NAT?
2- Has anyone running this kind of network and provide sample config for ASA 5520?
Regsrds,
Solved! Go to Solution.
12-14-2012 09:10 AM
Hi,
I suggest doing NAT on both sites.
For Site A with ASA running 8.4 software the NAT configuration might look something like this
Base Information
Configuration
object network LAN-LOCAL
subnet 192.168.1.0 255.255.255.0
object network LAN-NAT
subnet 10.1.1.0 255.255.255.0
object network REMOTE-LAN
subnet x.x.x.x 255.255.255.0
nat (inside,outside) source static LAN-LOCAL LAN-NAT destination static REMOTE-LAN REMOTE-LAN
What the above configuration will do is
As I said before I would suggest you ask the Site B admin to also NAT their local LAN 192.168.1.0/24 to something and then you can use that network range and insert to the above configuration to the place of x.x.x.x.
Please rate if you found the information helpfull
Also ask more if needed
- Jouni
12-14-2012 05:12 AM
Hi,
Some questions
I guess you could use Static NAT to NAT Site A and B both to their own /24 NAT networks. I would personally start with this.
This would mean that if host 192.168.1.100 on Site A uses the L2L VPN it will show up as NAT IP x.x.x.100 and so forth. Same for the Site B. If you want to connect to a host there which has the real IP of 192.168.1.200 the actual NAT IP address would be y.y.y.200
EDIT: For DHCP to work over this connection I'd imagine you need to forward the DHCP messages as unicast instead of broadcast. In other words, you need a router with "ip helper-address" configuration on the LAN interfaces.
I'm not 100% sure would the ASA handle such a thing through VPN. Might be able to use the DHCP relay on ASA but I have never tried to configure it. I think that there was some Cisco employee document about it on the forums though.
- Jouni
12-14-2012 08:05 AM
Thanks Jouni,
We only manage site A ASA version 8.4.Please can you paste some sample config for NAT(Static NAT to NAT Site A and B both to their own /24 NAT networks) as you sugussted.
Regsrds,
12-14-2012 09:10 AM
Hi,
I suggest doing NAT on both sites.
For Site A with ASA running 8.4 software the NAT configuration might look something like this
Base Information
Configuration
object network LAN-LOCAL
subnet 192.168.1.0 255.255.255.0
object network LAN-NAT
subnet 10.1.1.0 255.255.255.0
object network REMOTE-LAN
subnet x.x.x.x 255.255.255.0
nat (inside,outside) source static LAN-LOCAL LAN-NAT destination static REMOTE-LAN REMOTE-LAN
What the above configuration will do is
As I said before I would suggest you ask the Site B admin to also NAT their local LAN 192.168.1.0/24 to something and then you can use that network range and insert to the above configuration to the place of x.x.x.x.
Please rate if you found the information helpfull
Also ask more if needed
- Jouni
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: