VPN-NAT question

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

VPN-NAT question

L4 Transporter

I have 10.240.0.0/12 in the Proxy ID and would like to NAT all my 192.168.x.x addresses behind  10.248.250.10 out of that 10.240/12.
my plan is to create the NAT rule and assign that 10.248.250.10 to the VPN tunnel Interface. will this create a route to whole 10.240/12 or just 10.248.250.10? I have active networks on 10.240 subnet. so trying to be cautious before making the change.

 

TIA.

4 REPLIES 4

Cyber Elite
Cyber Elite

Use 10.248.250.10/32 as IP on tunnel interface. Then you are fine.

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

thank you. I will try this and let you know the result.

 

@Raido_Rattameister without even putting that IP on the interface, I am able to ping the endpoint on other side. 

we have just unidirectional traffic from my side to the other. I think that's the reason it worked.

You need IP on tunnel interface only if you do dynamic routing or tunnel monitoring. 

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011
  • 4323 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!