cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
240
Views
0
Helpful
0
Replies

ASA EZVPN Server and NAT exempt

n.oneill
Level 1
Level 1

Is it possible to NAT exempt EZVPN traffic without having to configure a NAT rule?

 

We are using EZVPN as an emergency backup solution for remote sites and I want to keep the configuration work to a minimum which is why I elected to use EZVPN in Network Extention Mode as it does not require any re-configuration on the ASA once the intial EZVPN config is in place.  When we deploy this we reconfigure the LAN interface on the router (EZVPN client) and the VPN comes up but VPN traffic is being subject to NAT. I was hoping there would be a NAT exempt checkbox on the ASA (EZVPN Server) for this traffic but I cannot see where this is configured.

 

I do have this working but I have had to configure a generic NAT rule on the ASA for traffic sourced and destined to RFC 1918 address space.  Is there a way to configure NAT exempt for EZVPN traffic and remove this rule?

0 Replies 0