01-31-2011 06:54 PM
I have a question on how traffic gets match and in which order for a L2L tunnel. See the attached diagram. On the ASA5520 side I have configured the 192.168.12.0/24 subnet to NAT to 10.252.43.0/24 addresses as follows:
global (outside) 1 10.252.43.0 netmask 255.255.255.0
nat (inside) 1 192.168.12.0 255.255.255.0
Now I want to send traffic from the 192.168.12.0/24 subnet to the 10.10.26.0/24 subnet over the tunnel. Which addresses do I match on the ASA5520 side of the tunnel?
I'm not sure if it should be:
access-list to_pix525 extended permit ip 192.168.12.0 255.255.255.0 10.10.26.0 255.255.255.0
or
access-list to_pix525 extended permit ip 10.252.43.0 255.255.255.0 10.10.26.0 255.255.255.0
Thanks,
-mike
Solved! Go to Solution.
02-01-2011 10:01 AM
Please change the nat0inside acl as follows:
access-list nat0inside extended permit ip 192.168.12.0 255.255.255.0 10.10.26.0 255.255.255.0
Everything else is fine.
--
Ramya
--please rate the solutions.
01-31-2011 07:33 PM
Hello Mike,
You need to use the second one, but you can initiate traffic from the 5520 side only.
If you want to initiate traffic from both sides, then configure a nat exemption for the VPN traffic and use the first acl.
-
Ramya
-- Please rate the solutions
02-01-2011 06:16 AM
Ramya,
Thanks for the reply. I want both sides to be able to initiate traffic. Would this be the correct [truncated] configuration?
global (outside) 1 10.252.43.0 netmask 255.255.255.0
nat (inside) 1 192.168.12.0 255.255.255.0
nat (inside) 0 access-list nat0inside
access-list nat0inside extended permit ip 10.252.43.0 255.255.255.0 10.10.26.0 255.255.255.0
access-list to_pix525 extended permit ip 192.168.12.0 255.255.255.0 10.10.26.0 255.255.255.0
crypto map VPN 1 match address to_pix525
crypto map VPN interface outside
-mike
02-01-2011 10:01 AM
Please change the nat0inside acl as follows:
access-list nat0inside extended permit ip 192.168.12.0 255.255.255.0 10.10.26.0 255.255.255.0
Everything else is fine.
--
Ramya
--please rate the solutions.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide