FirewallWizards
[Top] [All Lists]

[fw-wiz] bypassing PIX limitation

To: Firewall Wizards Security Mailing List <firewall-wizards@listserv.cybertrust.com>
Subject: [fw-wiz] bypassing PIX limitation
From: Paolo Supino <paolo@actcom.net.il>
Date: Wed, 08 Nov 2006 19:22:56 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Reply-to: paolo@actcom.net.il, Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
User-agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.12) Gecko/20050915
Hi

  I have a network that is protected by a PIX 515e running 6.3(1). I was 
asked to setup a IPSEC VPN with a partner. The partner's security policy 
mandates that  a remote encryption domain must use IP addresses on a 
subnet carved out of their overall IP network range. The network behind 
my PIX uses IP addresses on a subnet that is outside of their IP 
network. Adding a second IP to my network isn't supported by the PIX OS. 
To bypass this limitation I thought of NATing packets going into the VPN 
tunnel.  I've been looking for documentation for such a scenario, but 
can't find anything. Can packets going into a VPN tunnel be NATed?







TIA
Paolo

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>