08-27-2012 08:20 AM - edited 03-21-2019 06:12 AM
Just discovered that CCA doesn't add route-map to static PAT entries into CLI, like it does on dynamic nat entry. Route-map bypasses NAT for remote VPN site-to-site networks. Without route-map on static-nats, remote users can't access the PATted server IP and port through the site-to-site VPN. If I manually add route-map to the static PAT entry, it starts to work. I just opened a case with SBCS team and asked them file the bug. Has anyone seen this before?
08-27-2012 08:30 AM
Have you tried setting up EZ-VPN server and Client Mode using NEM? Using NEM will allow the VPN'ed users to access the server without using NAT.
08-27-2012 09:05 AM
Right, but I want to stay with CCA's Multi-site manager configuration.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide