fw1 site to site vpn subnet conflict

"zoe" <[email protected]> Wed, 30 Aug 2006 17:30:26 +0100
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
This is a multi-part message in MIME format.

--===============1084142444==
Content-Type: multipart/alternative;
	boundary="----=_NextPart_000_001C_01C6CC59.FB15BFA0"

This is a multi-part message in MIME format.

------=_NextPart_000_001C_01C6CC59.FB15BFA0
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

Hi
 
I have a site to site vpn with a client (fw1 at each end). I only have one
private subnet behind my firewall but my client has many and 
one of these conflicts with mine. 
Initially I only needed this connection to work one way (us --> them) so I
put a manual nat rule in place which hide nats my /24 behind 
a different private /24 for connections to the client. This works fine
 
Now I have been asked to enable inbound traffic to certain hosts from the
client (them --> us). They can't use the real addresses of my 
hosts as they would be routed to their own network. Any suggestions on how
this can be done (if at all)? I have tried a few things including adding
static nat inbound to the few hosts they need to access but have had no
success. I can post more config if anyone thinks they can help
 
Thanks
 
Zoe




 

------=_NextPart_000_001C_01C6CC59.FB15BFA0
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dus-ascii">
<META content=3D"MSHTML 6.00.2900.2963" name=3DGENERATOR></HEAD>
<BODY>
<DIV><FONT face=3DArial size=3D2>Hi</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>I have a site to site vpn with a client =
(fw1 at=20
each end). I only have one private subnet behind my firewall but my =
client has=20
many and <BR>one of these conflicts with mine. <BR>Init<SPAN=20
class=3D924292816-30082006>i</SPAN>ally I only needed this connection to =
work one=20
way (us --&gt; them) so I put a manual nat rule in place which hide nats =
my /24=20
behind <BR>a different private&nbsp;<SPAN class=3D924292816-30082006>/24 =

</SPAN>for connections to the client. This works fine</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Now I have been asked to enable inbound =
traffic to=20
certain hosts from the client (them --&gt; us). They can't use the real=20
addresses of my <BR>hosts as they would be routed to their own network. =
Any=20
suggestions on how this can be done (if at all)? I have tried a few =
things=20
including adding static nat inbound to the&nbsp;<SPAN=20
class=3D924292816-30082006>few </SPAN>hosts they need to access but have =
had no=20
success. I can post more config if anyone thinks they can =
help</FONT></DIV>
<DIV>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Thanks</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2>Zoe</FONT><BR><BR><BR><BR></DIV>
<DIV>&nbsp;</DIV></BODY></HTML>

------=_NextPart_000_001C_01C6CC59.FB15BFA0--


--===============1084142444==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
VPN mailing list
[email protected]
http://lists.shmoo.com/mailman/listinfo/vpn
--===============1084142444==--