FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] firewall-wizards Digest, Vol 7, Issue 9

To: firewall-wizards@listserv.icsalabs.com
Subject: Re: [fw-wiz] firewall-wizards Digest, Vol 7, Issue 9
From: Mikael Velschow-Rasmussen <mvr@nworks.dk>
Date: Sun, 12 Nov 2006 11:10:35 +0100
Cc: paolo@actcom.net.il
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.icsalabs.com
In-reply-to: <mailman.636.1163263979.16841.firewall-wizards@listserv.icsalabs.com>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Hi Paolo !!

Have you tried e.g.:

access-list 100 extended permit ip 172.28.150.32/28 172.28.x.x/16
global (outside) 1 interface 
static (inside,outside) 172.28.150.32/28 192.168.99.x/28
nat (inside) 1 0 0
crypto map <mapname> 10 match address 100

If you need to do the NAT dynamically i would try this:

access-list 100 extended permit ip 172.28.150.32/28 172.28.x.x/16
access-list 101 extended permit ip 192.168.99.x/24 172.28.x.x/16
nat (inside) 1 access-lists 101
nat (inside) 2 0 0
global (outside) 1 172.28.150.32/28
global (outside) 2 interface 
crypto map <mapname> 10 match address 100

NB: just typed it on top of my head so maybe there's some syntax errors.

Regards
Mikael Velschow-Rasmussen
M.Sc.e.e., CCIE #9973, CCSI #22493,
INFOSEC, SANS GCFW #0565, HP MASE
mvr@nworks.dk


That is what I thought of doing but I can't find any documentation on 
how to do it. Can you please direct me to documentation that show's how 
to NAT traffic going into a VPN?

TIA
Paolo

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>
  • Re: [fw-wiz] firewall-wizards Digest, Vol 7, Issue 9, Mikael Velschow-Rasmussen <=