11-01-2019 10:17 AM - edited 02-21-2020 09:39 AM
Hello all,
I'm setting up a VPN with a 3rd party who have suggested the use of 172.16.8.0/26 as the encryption domain on my side of the tunnel (happy to do this to avoid wasting public IP's). There side of the encryption domain is 70.0.0.x/27. I am planning on using the 192.168.1.0/24 range for my internal network. A requirement from the 3rd party is that there are 11 IP's configured as static NAT. My question is how would I implement this config so the static NAT's are in place and that the rest of the interesting traffic uses PAT? Also, can I actually NAT private to private and if so where does my public IP (213.0.0.x) come into the equation?
I have added what I believe is correct but i'm obviously not entirely sure :-
access-list internet_1_cryptomap line 1 extended permit ip host 192.168.1.0 70.0.0.1 255.255.255.224
nat (inside,outside) source static 192.168.1.0 172.16.8.0 destination static 70.0.0.0 70.0.0.0
Solved! Go to Solution.
11-04-2019 08:21 PM
11-02-2019 08:38 PM
11-04-2019 08:31 AM
Francisco,
Thanks for the prompt reply. So something like this :-
access-list internet_1_cryptomap line 1 extended permit 172.16.8.0 255.255.255.192 70.0.0.0 255.255.255.224
nat (inside,outside) source static 192.168.1.0 172.16.8.0 destination static 70.0.0.0 70.0.0.0
Also, if i'm trying to configure some static 1-to-1 NAT's (and leave the rest for PAT) would this be correct :-
nat (inside,outside) source static 192.168.1.1 172.16.8.1 destination static 70.0.0.0 70.0.0.0
nat (inside,outside) source static 192.168.1.2 172.16.8.2 destination static 70.0.0.0 70.0.0.0
nat (inside,outside) source static 192.168.1.3 172.16.8.3 destination static 70.0.0.0 70.0.0.0
nat (inside,outside) source static 192.168.1.4 172.16.8.4 destination static 70.0.0.0 70.0.0.0
.................
nat (inside,outside) source static 192.168.1.10 172.16.8.10 destination static 70.0.0.0 70.0.0.0
nat (inside,outside) source static 192.168.1.0 172.16.8.0 destination static 70.0.0.0 70.0.0.0 <<<<<<<<<PAT for the rest
Thanks in advance. Your help is greatly appreciated.
11-04-2019 08:21 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide