IPSEC VPN NAT issue

Reply
L4 Transporter

IPSEC VPN NAT issue

I have a VPN request where  peer's IP range is conflicting with one of my internal IP range. 

They are asking me if I can do a NAT on my end to resolve it but based on my experience it must be them who should do a NAT. 

please correct me if I'm wrong.

Highlighted
L4 Transporter

Re: IPSEC VPN NAT issue

Here is the way I would recommend that you do it...

 

Scenario is overlapping subnets on both side of IPSec Tunnel.

Both sides need to NAT, to give the remote sides a different appearance/subnet.

 

 

vpnnat.png

 

2) A different option may be (not sure) to only SNAT from the remote side, inbound to your environment.

 

Different from the top example.

Both remote and local sites have overlapping subnets.

 

when traffic from remote side enters your FW, you SNAT it, and send it, inbound to your network, with bidirectional enabled.

Now a user/server, etc, will send back traffic to the SNAT'd address, and your FW will strip off the SNAT and send to the correct source address, across the VPN.

 

Questions???

 

Let me know.

 

2ndoption.png

 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!