- Posts: 2
- Thank you received: 0
Cisco ASA 5505 for NAT-T as well as VPN termination
- nandagopalrvarma
- Topic Author
- Offline
- New Member
Less
More
14 years 3 months ago #35142
by nandagopalrvarma
Hi,
*internet*
[HP 7203dl1]
(Cisco asa 5505-1)
*Hp5203 L3 switch*---(HP 7203dl2)--L--L--(*HP7203dl3 remote*)---(unmanaged L2 switch)--(*Cisco ASA 5505-2*)--*10.175.1.0/24*
This is our network . We have terminated an IPSEC VPN on Cisco asa 5505-1 as a LL backup . It is working fine and no problems reported. My requirement is that we need to nat-t another IPSEC VPN from one our partners to the CISCO ASA 5505-2 ,as shown above. I have configured a static 1-1 NAT and inbound access rules allowing isakmp,udp 4500(nat-t) and ssh from the partner IP's to the NATed IP . Also enabled crypto isakmp nat-traversal 20 and inspect ipsec-pass-thru in case NAT-t does not work in the access list.
Please see the relevant config attached. Kindly advise.Cisco ASA 5505-1 has a base license,is in routed mode and runs asa-722-k8.bin image.
I am also not able to access vnc for another static NAted IP. Please help.
*internet*
[HP 7203dl1]
(Cisco asa 5505-1)
*Hp5203 L3 switch*---(HP 7203dl2)--L--L--(*HP7203dl3 remote*)---(unmanaged L2 switch)--(*Cisco ASA 5505-2*)--*10.175.1.0/24*
This is our network . We have terminated an IPSEC VPN on Cisco asa 5505-1 as a LL backup . It is working fine and no problems reported. My requirement is that we need to nat-t another IPSEC VPN from one our partners to the CISCO ASA 5505-2 ,as shown above. I have configured a static 1-1 NAT and inbound access rules allowing isakmp,udp 4500(nat-t) and ssh from the partner IP's to the NATed IP . Also enabled crypto isakmp nat-traversal 20 and inspect ipsec-pass-thru in case NAT-t does not work in the access list.
Please see the relevant config attached. Kindly advise.Cisco ASA 5505-1 has a base license,is in routed mode and runs asa-722-k8.bin image.
I am also not able to access vnc for another static NAted IP. Please help.
- nandagopalrvarma
- Topic Author
- Offline
- New Member
Less
More
- Posts: 2
- Thank you received: 0
14 years 3 months ago #35145
by nandagopalrvarma
Replied by nandagopalrvarma on topic Re: Cisco ASA 5505 for NAT-T as well as VPN termination
I think I missed the config attachment. Sorry here it is.
Time to create page: 0.112 seconds