08-22-2012 10:18 PM
Dear All,
I have a requirement to configure Site-to-Site VPN with HO. i have my internet link termintaed on router and got only one public ip. my ASA is behind this router with no public ip (attached diagram). This router will not support VPN and i need to configure VPN on firewall.
192.168.20.0/24 is the network between router and firewall. 192.168.10.0/24 is inside network. ( attached diagram have the full details)
Please advice the configuration to achive this.....
Thanks in Advance..
Shanil
Solved! Go to Solution.
08-23-2012 06:25 AM
If it's cisco router then the configuration would be:
ip nat inside source static udp 192.168.20.2 500 interface
ip nat inside source static udp 192.168.20.2 4500 interface
08-23-2012 02:35 AM
Do you have a spare public ip on the router, or it is just one IP assigned to the router outside interface?
You can configure either static NAT or static PAT on the router for the ASA outside interface IP, then you can configure site-to-site VPN tunnel.
If you are to configure static PAT, you need the following port to be statically PATed:
UDP/500 and UDP/4500
08-23-2012 05:19 AM
Thanks Jennifer..
I dont have any spare public ip.there just one IP assigned to the router outside interface.would you please advice the configuration for the required NAT?
Thanks
Shanil
08-23-2012 06:25 AM
If it's cisco router then the configuration would be:
ip nat inside source static udp 192.168.20.2 500 interface
ip nat inside source static udp 192.168.20.2 4500 interface
08-24-2012 01:35 AM
Thank you very much Jennifer..
Regards
Shanil
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide