fw1 site to site vpn subnet conflict
"zoe" <[email protected]> Wed, 30 Aug 2006 17:30:26 +0100
| Newsgroups | gmane.comp.security.vpn |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --===============1084142444== Content-Type: multipart/alternative; boundary="----=_NextPart_000_001C_01C6CC59.FB15BFA0" This is a multi-part message in MIME format. ------=_NextPart_000_001C_01C6CC59.FB15BFA0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Hi I have a site to site vpn with a client (fw1 at each end). I only have one private subnet behind my firewall but my client has many and one of these conflicts with mine. Initially I only needed this connection to work one way (us --> them) so I put a manual nat rule in place which hide nats my /24 behind a different private /24 for connections to the client. This works fine Now I have been asked to enable inbound traffic to certain hosts from the client (them --> us). They can't use the real addresses of my hosts as they would be routed to their own network. Any suggestions on how this can be done (if at all)? I have tried a few things including adding static nat inbound to the few hosts they need to access but have had no success. I can post more config if anyone thinks they can help Thanks Zoe ------=_NextPart_000_001C_01C6CC59.FB15BFA0 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD> <META http-equiv=3DContent-Type content=3D"text/html; = charset=3Dus-ascii"> <META content=3D"MSHTML 6.00.2900.2963" name=3DGENERATOR></HEAD> <BODY> <DIV><FONT face=3DArial size=3D2>Hi</FONT></DIV> <DIV> </DIV> <DIV><FONT face=3DArial size=3D2>I have a site to site vpn with a client = (fw1 at=20 each end). I only have one private subnet behind my firewall but my = client has=20 many and <BR>one of these conflicts with mine. <BR>Init<SPAN=20 class=3D924292816-30082006>i</SPAN>ally I only needed this connection to = work one=20 way (us --> them) so I put a manual nat rule in place which hide nats = my /24=20 behind <BR>a different private <SPAN class=3D924292816-30082006>/24 = </SPAN>for connections to the client. This works fine</FONT></DIV> <DIV> </DIV> <DIV><FONT face=3DArial size=3D2>Now I have been asked to enable inbound = traffic to=20 certain hosts from the client (them --> us). They can't use the real=20 addresses of my <BR>hosts as they would be routed to their own network. = Any=20 suggestions on how this can be done (if at all)? I have tried a few = things=20 including adding static nat inbound to the <SPAN=20 class=3D924292816-30082006>few </SPAN>hosts they need to access but have = had no=20 success. I can post more config if anyone thinks they can = help</FONT></DIV> <DIV> </DIV> <DIV><FONT face=3DArial size=3D2>Thanks</FONT></DIV> <DIV><FONT face=3DArial size=3D2></FONT> </DIV> <DIV><FONT face=3DArial size=3D2>Zoe</FONT><BR><BR><BR><BR></DIV> <DIV> </DIV></BODY></HTML> ------=_NextPart_000_001C_01C6CC59.FB15BFA0-- --===============1084142444== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ VPN mailing list [email protected] http://lists.shmoo.com/mailman/listinfo/vpn --===============1084142444==--