03-11-2019 05:01 AM
Hi,
we have to make two vpn in overlapped network, example:
My lan
192.168.0.0/24
Remote1
192.168.0.0/24
Remote2
192.168.0.0/24
I have control only in my side of vpn, Remote1 and Remote2 can't make nat or change in firewall.
I have an Asa 9.1
I make destination nat , but i need to insert in vpn traffic selection, the natted ip address to make decision
in which tunnel pass the traffic.
In normal situation, nat is make before vpn, so i need to insert in traffic selection the real remote ip.
If i insert the natted ip, i have phase1 up but phase2 not work (no_proposal_choosen)
How i can resolve this?
Thanks
03-11-2019 06:10 AM
cant take credit for it, but check:
https://community.cisco.com/t5/vpn-and-anyconnect/vpn-overlapping/td-p/3034196
03-11-2019 07:26 AM
In all example i see, i see to make a source nat to match traffic selection but in my case in inpossible...
I neet to make destination nat after ipsec , to specify natted address in my ipsec traffic selection
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide