NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [FW1] NAT across a VPN



 
Seeing as the encapsulation happens last on the outbound, and first on the
inbound, can't we just translate one of the lans behind a static pool?
 
I guess that is the question being asked.
 
I can't see any reason why it shouldn't work.
 
Paul.
 

-----Original Message-----
From: [email protected] [mailto:[email protected]]
Sent: 05 October 2000 15:07
To: [email protected]
Subject: [FW1] NAT across a VPN






I read Frank's post and while I am testing this in our lab I wanted to see 
if anyone had come up with a solution already. 

Problem: 
local-net 10.10.10.0 
partner-net 10.10.10.0 
IKE VPN 

Is it possible to NAT either you or your partner -net, BEFORE or after it 
crosses the VPN ? 

Objective: 
To allow a VPN between two companies without re-addressing either company. 

Jon 


Date: Wed, 4 Oct 2000 22:38:56 -0500 
From: Frank Knobbe <[email protected]> 
Subject: RE: [FW1] VPN + NAT 

- -----BEGIN PGP SIGNED MESSAGE----- 
Hash: SHA1 

For these types of VPN's you probably want to add two Translation 
rules that disable NAT for connections through the VPN tunnel. The 
two rules are: 

MyNet - PartnerNet - Any - Original - Original - Any 
PartnerNet - MyNet - Any - Original - Original - Any 

Make sure you set routes in your network that directs traffic aimed 
at the PartnerNet to your firewall. 

Regards, 
Frank 




============================================================================
==== 
     To unsubscribe from this mailing list, please see the instructions at 
               http://www.checkpoint.com/services/mailing.html
<http://www.checkpoint.com/services/mailing.html>  
============================================================================
==== 

---------------------------------------------------------------------------------
This e-mail is intended only for the above addressee. It may contain
privileged information. If you are not the addressee you must not copy,
distribute, disclose or use any of the information in it. If you have
received it in error please delete it and immediately notify the
sender.

evolvebank.com is a division of Lloyds TSB Bank plc.
Lloyds TSB Bank plc, 71 Lombard Street, London EC3P 3BS.  Registered in
England, number 2065.  Telephone No: 020 7626 1500
Lloyds TSB Scotland plc, Henry Duncan House, 120 George Street,
Edinburgh EH2 4LH. Registered in Scotland, number 95237.  Telephone
No:Lloyds TSB Bank plc and Lloyds TSB Scotland plc are regulated by the
Personal Investment Authority and represent only the Scottish Widows
and Lloyds TSB Marketing Group for life assurance, pensions and
investment business.

Members of the UK Banking Ombudsman Scheme and signatories to the UK
Banking Code.
----------------------------------------------------------------------------------


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents � 2003 Network Presence, LLC. All rights reserved.