cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
492
Views
0
Helpful
4
Replies

Static nat and vpn issue

carllougher
Level 1
Level 1

I have a static nat for inbound smtp traffic and inbound vpn smtp traffic no longer works even though my access list denys vpn traffic being natted.

Config attached.

Any way around this?

Taf..

4 Replies 4

andyjames
Level 1
Level 1

Are you going to use the vpn for SNMP traffic only?

If so take the translation off.

If not would need to see config for remote end also.

Andy.

Smtp required for both external and vpn access. The issue is that the inbound vpn smtp traffic trys to use the Nat rule and therefore doesnt work.

I cant see anyway around this and it doesnt do it with a pix.

Collin Clark
VIP Alumni
VIP Alumni

You need to do policy routing. This link should help.

http://www.enterastream.com/whitepapers/cisco/pix/pix-practical-guide.html

I dont see how policy routing or routemaps are going to make any difference because the traffic is still getting forwarded to the same interface ie the dialer interface. Only difference is that it needs to go through the VPN. In the config attached there is an access-list which denys traffic to the vpn from going through the nat translation but for some reason this doesnt apply if there is a static nat applied.