cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
436
Views
5
Helpful
2
Replies

cant ping Static NAT private address in Site to Site IPSec VPN

angel.tagra
Level 1
Level 1

I have 2 sites A and B, A is using Cisco IOS and B is using PIX. IPsec tunnel already up and running. Site A is using cisco 2600 and site B is PIX. Both sites can ping each other private ip address.

Also on both site NAT is configured for internet and static NAT for Web Server. Site A is configured with static NAT for the mentioned Web Server. All internet connectivity are working fine. But Site B wont be able to ping to the private ip address of site A wherein static NAT is configured. Everytime I take the static NAT then site B would be able to ping the private IP address.

My question is what kind of static NAT should I apply so that both internet and IPSec traffic would be able to go thru. Thanks.

2 Replies 2

a.awan
Level 4
Level 4

Read the following article which explains how static NAT can cause issues in an IPSec configuration. The problem occurs because of the NAT Order of operation. The article also provides a solution for it:

http://www.cisco.com/en/US/tech/tk583/tk372/technologies_configuration_example09186a0080094634.shtml#loopback

Thanks a million it really solve my problem.