cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
224
Views
0
Helpful
2
Replies

How to limit NAT to only 1 VPN tunnel

Stewart Rae
Level 1
Level 1

I am new to the Cisco ASA having used the Nortel Contivity VPN routers for years.   I need to NAT an inside host for a particular VPN tunnel to a support vendor.   I have create NAT objects, but I now realize that they are NAT for everyone and not just this particular VPN tunnel.

How do I limit my NAT'ing to a particular VPN tunnel.

 

Thank you in advance,

 

Stewart Rae

2 Replies 2

David paull
Level 1
Level 1

A lot of times, I'll see partners use a sole 5505 for a new site to site connection...probably for this reason.

 

Depending on what ASA version your device is running, you may be able to use twice nat -- that will nat the traffic based on source and destination independently of say a packet from the same source destined for another location.

 

 

AllertGen
Level 3
Level 3

Hello, .

Can you show ACL for your NAT rules? I think you used ACL based on the source with any destination. Just change rules at this ACL to lines with source of your network and destination behind the VPN.

Best Regards.