IPSEC VPN NAT issue

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

IPSEC VPN NAT issue

L4 Transporter

I have a VPN request where  peer's IP range is conflicting with one of my internal IP range. 

They are asking me if I can do a NAT on my end to resolve it but based on my experience it must be them who should do a NAT. 

please correct me if I'm wrong.

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Here is the way I would recommend that you do it...

 

Scenario is overlapping subnets on both side of IPSec Tunnel.

Both sides need to NAT, to give the remote sides a different appearance/subnet.

 

 

vpnnat.png

 

2) A different option may be (not sure) to only SNAT from the remote side, inbound to your environment.

 

Different from the top example.

Both remote and local sites have overlapping subnets.

 

when traffic from remote side enters your FW, you SNAT it, and send it, inbound to your network, with bidirectional enabled.

Now a user/server, etc, will send back traffic to the SNAT'd address, and your FW will strip off the SNAT and send to the correct source address, across the VPN.

 

Questions??? 😛

 

Let me know.

 

2ndoption.png

 

Help the community: Like helpful comments and mark solutions

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Here is the way I would recommend that you do it...

 

Scenario is overlapping subnets on both side of IPSec Tunnel.

Both sides need to NAT, to give the remote sides a different appearance/subnet.

 

 

vpnnat.png

 

2) A different option may be (not sure) to only SNAT from the remote side, inbound to your environment.

 

Different from the top example.

Both remote and local sites have overlapping subnets.

 

when traffic from remote side enters your FW, you SNAT it, and send it, inbound to your network, with bidirectional enabled.

Now a user/server, etc, will send back traffic to the SNAT'd address, and your FW will strip off the SNAT and send to the correct source address, across the VPN.

 

Questions??? 😛

 

Let me know.

 

2ndoption.png

 

Help the community: Like helpful comments and mark solutions
  • 1 accepted solution
  • 5875 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!