Hi, Has anyone setup two PAN FW point to point that connect with the same subnets on each side. The reason for the same subnets is that we have our production network behind FW-A and a co-location network that mirrors our production network behind FW-B. This is for disaster recovery and quick turn on of machines in the event of a disaster, etc. I have the tunnel setup between two FWs, but I am having difficulty in getting NAT & Routing working appropriately to communicate with each other. Unfortunately I am not at work to post screen shots of my setup at the moment, but wanted to see if someone could give some insight as to how to set this up. I have followed the document here: - but have not had any success. I am trying to NAT a pool of addresses to another pool on the other side. For example: Our Trust network is a 192.168.0.0/16 - I want to NAT these addresses through 10.168.0.0/16 to the other side of the tunnel and reverse the NAT to be directed to the same 192.168.0.0/16 address. I've tried assigning IP address ranges to each tunnel, and using the NAT rule to NAT the 192.168.0.0/16 destined for 10.168.0.0/16 to a 10.250.0.0/16 translated at the source. I think this all works, but my routes don't seem to work, and don't know what the route would be. I tried both the 10.168.0.0/16 and the 10.250.0.0/16 destination to the tunnel interface. Neither seem to get it working. I tried same tunnel designators (tunnel.10) for example on the same side as well as the 10.250.0.0/16 and a 10.251.0.0/15 on both local tunnel address (FW-A), as well as on the far end tunnel (FW-B) I can post more tomorrow, but NATing this way isn't really explained in the above document, and there really is no explanation for the 10.2.1.0/24 network in the same document, so I am unsure how that all fits into this. Also I don't understand the ike-to-gw route rule either. I tried adding this with no luck. Can anyone help? I'm somewhat in need of getting this project setup and am completely confused. I wish there was a clearer, more up to date document regarding this. Surely others are doing this as well? Thanks in advance.
... View more