cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
741
Views
0
Helpful
1
Replies

NAT before IPSEC

jbrunstein
Level 1
Level 1

Hello

Is it possible on a PIX 6.3 , to have the source address translated before the frame would be encapsulated in an IPSec tunnel ?

If yes, how you do it ?

Regards

1 Reply 1

srue
Level 7
Level 7

yes. create your NAT statements how you normally would. then, configure your crypto ACL's to match the newly NAT'ed addresses instead of the actual IP's.

you can also use policy nat for you ipsec tunnels, but I dont know the details of your setup so I can't say if that's what you'd need or not.