cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
961
Views
5
Helpful
1
Replies

Cisco Router outside nat with vpn

kogutier92
Level 1
Level 1

Hi All,

 

I hope you are doing well,

 

I am writing this post to ask for your kind help to help me figure out some configuration request.

 

I have an IPsec l2l ikev2 tunnel between two routers; they are requesting me to nat the client network that comes through the ipsec vpn tunnel to our ISR 4331 on the outside/internet facing interface, to our internal monitoring server, they are requesting this because the client network segments is the same as on of our internal networks. Is this something that can be achieved on our ISR 4331 router using the ip nat source list command? or is there anyway to workaround this?

 

Thanks

 

 

 

 

Untitled Diagram.png

1 Reply 1

jamesjack
Level 1
Level 1

This section presents you with the information to configure the features this document describes. Note: Use the Command Lookup Tool (registered customers only) to find additional information on the commands that this document uses. Network Diagram This document uses this network setup. 2a.gif When you issue a ping sourced from Router 2514W's Loopback1 interface destined to Router 2501E's Loopback0 interface, this is what happens: On the outside interface (S1) of Router 2514X, the ping packet shows up with a Source Address (SA) of 172.16.89.32 and a Destination Address (DA) of 171.68.1.1. NAT translates the SA to the Outside Local Address 171.68.16.5 (according to the ip nat outside source static command configured on Router 2514X). Router 2514X then checks its routing table for a route to 171.68.1.1. If the route does not exist, Router 2514X drops the packet. In this case, Router 2514X has a route to 171.68.1.1 through the static route to 171.68.1.0. It forwards the packet to the destination. Router 2501E sees the packet on its incoming interface (E0) with an SA of 171.68.16.5, and a DA of 171.68.1.1. It responds by sending an Internet Control Message Protocol (ICMP) echo reply to 171.68.16.5. If it does not have a route, it drops the packet. However, in this case it has the (default) route. Therefore, it sends a reply packet to Router 2514X, using an SA of 171.68.1.1, and a DA of 171.68.16.5. Router 2514X sees the packet and checks for a route to the 171.68.16.5 address. If it does not have one, it responds with an ICMP unreachable reply. In this case, it has a route to 171.68.16.5 (due to the static route).omegle tv. It therefore translates the packet back to the 172.16.89.32 address, and forwards it out its outside interface (S1).

jamesjack
Review Cisco Networking for a $25 gift card