cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
450
Views
0
Helpful
2
Replies

9.0 can a dynamic nat be used over ipsec vpn?

Chris Izatt
Level 1
Level 1

9.0 can a  dynamic nat be used over ipsec vpn?

 

we have a vpn up and working between two asa's and when we run the traffic through a static nat rule the traffic passes over the vpn. When we use a dynamic nat the traffic does not get picked up by the vpn ACL. 

 

we are disabling the nat rules to switch back and forth so even when we use the same source destination the result is the same. 

 

Am I missing something with 9.0 code versions? If i disable all nats and pass the traffic it goes over the vpn. 

 

So it seems when using the dynamic nat statement it pushes the traffic to the outside interface without looking at the vpn acl. Please let me know if I am off base I am a newb on post 8.3 code. 

 

Thanks

1 Accepted Solution

Accepted Solutions

rizwanr74
Level 7
Level 7

Have you included the natted ip address or range into the crytop acl?

Have you permitted natted ip address or range in the other end of the tunnel?

 

 

View solution in original post

2 Replies 2

rizwanr74
Level 7
Level 7

Have you included the natted ip address or range into the crytop acl?

Have you permitted natted ip address or range in the other end of the tunnel?

 

 

I didn't do that at first because I remember reading something about in ver 9 to only use the unnatted IP because of order of ops. That seemed weird to me at the time. 

Yes it seems that you need the nat ip like always. Should have just went with my gut on that. 

 

Thanks