[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] RE: [FW1] NAT across a VPN
Seeing as the encapsulation happens last on the outbound, and first on the inbound, can't we just translate one of the lans behind a static pool? I guess that is the question being asked. I can't see any reason why it shouldn't work. Paul. -----Original Message----- From: [email protected] [mailto:[email protected]] Sent: 05 October 2000 15:07 To: [email protected] Subject: [FW1] NAT across a VPN I read Frank's post and while I am testing this in our lab I wanted to see if anyone had come up with a solution already. Problem: local-net 10.10.10.0 partner-net 10.10.10.0 IKE VPN Is it possible to NAT either you or your partner -net, BEFORE or after it crosses the VPN ? Objective: To allow a VPN between two companies without re-addressing either company. Jon Date: Wed, 4 Oct 2000 22:38:56 -0500 From: Frank Knobbe <[email protected]> Subject: RE: [FW1] VPN + NAT - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 For these types of VPN's you probably want to add two Translation rules that disable NAT for connections through the VPN tunnel. The two rules are: MyNet - PartnerNet - Any - Original - Original - Any PartnerNet - MyNet - Any - Original - Original - Any Make sure you set routes in your network that directs traffic aimed at the PartnerNet to your firewall. Regards, Frank ============================================================================ ==== To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html <http://www.checkpoint.com/services/mailing.html> ============================================================================ ==== --------------------------------------------------------------------------------- This e-mail is intended only for the above addressee. It may contain privileged information. If you are not the addressee you must not copy, distribute, disclose or use any of the information in it. If you have received it in error please delete it and immediately notify the sender. evolvebank.com is a division of Lloyds TSB Bank plc. Lloyds TSB Bank plc, 71 Lombard Street, London EC3P 3BS. Registered in England, number 2065. Telephone No: 020 7626 1500 Lloyds TSB Scotland plc, Henry Duncan House, 120 George Street, Edinburgh EH2 4LH. Registered in Scotland, number 95237. Telephone No:Lloyds TSB Bank plc and Lloyds TSB Scotland plc are regulated by the Personal Investment Authority and represent only the Scottish Widows and Lloyds TSB Marketing Group for life assurance, pensions and investment business. Members of the UK Banking Ombudsman Scheme and signatories to the UK Banking Code. ---------------------------------------------------------------------------------- ================================================================================ To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================================================
|