cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1406
Views
20
Helpful
32
Replies
Contributor

Re: Add new subnets to site to site VPN tunnel are already created.

I take it no NAT exemption is done if no NATTING is being done for any of the local source subnets for the IPSEC tunnel correct?
VIP Advisor RJI VIP Advisor
VIP Advisor

Re: Add new subnets to site to site VPN tunnel are already created.

@CiscoBlueBelt If you do not have NAT configured at all then you would not need a NAT exemption rule. You would need a NAT exemption if you have a dynamic NAT in your configuration (i.e. for internet access), that could potentially NAT outbound traffic. The NAT exemption rule would need to be placed above the dynamic NAT rule in order to be effective.

 

HTH

Highlighted
Contributor

Re: Add new subnets to site to site VPN tunnel are already created.

In reference to IPSEC VPN, I have the following, the DM objects are being natted to itself correct? I can replace the DM objects with a object-group containing both those objects correct? Why does X.X.X.30_new appear twice?
nat (inside,outside) source static DM_INLINE_NETWORK_1 DM_INLINE_NETWORK_1 destination static X.X.X.30_object X.X.X.30_object