NATting both ways

I have a 2811s doing many VPNs to partners and clients. These routers are on my "VPN" network off a PIX 525. I use static routes on the PIX to get the traffic from my networks to the appropriate router and then down the VPN. This has been the setup for years here. It works well and is predictable.
All the VPNs are built using crypto maps. We use a combination of dynamic and static NATs (depending on connection direction) to a public address range we own specifically for these VPN NATs. Our partners and clients also use public address in the VPNs so we never have private range conflicts. We are using ip nat inside and ip nat outside on our inside and outside identified interfaces.
Recently, this model broke down. I knew this would eventually show its ugly head. We have a client that will access a machine behind our pix over the internet from a public source address (let's say 20.20.20.20). We also have a machine that needs to access this same address (20.20.20.20) over a VPN. As all the routing takes place on the PIX, if I route 20.20.20.20 to a VPN router, then the over-the-internet connections no longer work (their SYN packet comes over the internet, but my reply SYN-ACK routes to the VPN tunnel).
My solution is to use NAT. Instead of our opening connections to 20.20.20.20, we would open connections to a private address (let's say 10.0.0.20) that would route to the VPN router and it would then NAT it to 20.20.20.20 and send it down the tunnel. So I'd basically have two NATs happening on this router. One NAT from my source private to my source public and another NAT from my destination private (10.0.0.20) to their destination public (20.20.20.20).
Since I'm using ip nat inside on my inside interface and ip nat outside on my outside interface, is this possible? Should I use ip nat outside source static command?
Any help would be greatly appreciated.

NATting both ways may not help you. Check if you have configured Hairpinning properly on the PIX. Following link may help you
http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807e0aca.shtml#ra-sol-2

Similar Messages

  • I am synching my ipad and iphone with icloud. Events put in calendar go to the iphone, but if i enter an event on the iphone, it does not go to the ipad. What do i do to get this to work both ways?

    I am synching my ipad and iphone with icloud. Events put in calendar on ipad  go to the iphone calendar,, but if i enter an event on the iphone calendar, it does not go to the ipad. What do i do to get this to work both ways?

    OK Vicky, good clues...
    See if this helps...
    Open Keychain Access in Utilities, use Keychain First Aid under the Keychain Menu item, then either check the Password under that item, change it, or delete it and start over. See if there are duplicates, should be one for Incoming & one for Outgoing.
    Resetting your keychain in Mac OS X...
    If Keychain First Aid finds an issue that it cannot repair, or if you do not know your keychain password, you may need to reset your keychain.
    http://support.apple.com/kb/TS1544

  • How to unlock the screen of my iphone to see photos in both ways vertical

    how to unlock the screen of my iphone to see my photos in both ways, vertical & horizontal ?

    Turn off Portrait Lock in Control Center.

  • I have tried both ways to enable Firefox as default Browser; neither work. What can I do?

    I am unable to get Firefox enabled as default Browser. Both Firefox tells me that it is now my default Browser; IE states that IE is not the default Browser: but, all links in e-mails go through IE and not Firefox. I tried both ways to enable default, [1] through Internet Options, and [2] through the Control Panel's Add/Remove as recommended. Still doesn't work. How can I get IE disconnected as the de facto default Browser? I am running XP-SP3 , IE-8 & Firefox 6.

    In IE, open the Internet Options dialog (it will be in the Tools menu), then in the Internet options dialog, go to the Programs tab and click the "Make default" button.

  • Events entered on my iphone calendar do not appear on my ipad calendar, but events entered the other way around (on Ipad DO appear instantly on my phone calendar. How can I get these calendars to sync both ways instantly?

    Events entered on my iphone calendar do not appear on my ipad calendar, but events entered the other way around (on Ipad DO appear instantly on my phone calendar. How can I get these calendars to sync both ways instantly?

    If you're trying to sync an iCloud calendar, go to Settings>Mail,Contacts,Calendars>Default Calendar on your iPhone and make sure you have selected your iCloud calendar as your default.

  • Does Sync works both ways (Android to PC)?

    I've installed Firefox for Android for the first time. I logged into Sync, and pretty soon I could access all my PC bookmarks on my Android phone.
    I then bookmarked a page on the phone, but I can't find it on my PC still (it's been several hours).
    Does the Sync work both ways (Android to PC also)?

    Important: Firefox Sync requires the latest version of Firefox. Make sure you have updated Firefox on any computer or Android device.

  • I am not able to sync my outlook contacts with my iphone (both ways) noting that the calendar and notes are suncing perfectly (both ways)?

    I am not able to sync my outlook contacts with my iphone (both ways) noting that the calendar and notes are suncing perfectly (both ways)?

    You cannot sync Outlook 2011 directly with an iPhone, but if you go to the Tools menu and choose Sync Services, you can have Outlook sync with iCal and Address Book, which will then sync with the iPhone. And if your business is using Microsoft Exchange, you can set the iPhone up to communicate and sync directly with the Exchange server.
    Regards.

  • TS4185 Just downloaded FACETIME on my 4yr. olf Imac running Snow Leopard. When making a call to my friend's Imac all works correctly going both ways. When my wife calls me via Facetime from her Ipad, I cannot click on "accept"- not there?

    Just downloaded FACETIME on my 4yr. olf Imac running Snow Leopard. When making a call to my friend's Imac all works correctly going both ways. When my wife calls me via Facetime from her Ipad, I cannot click on "accept"- not there? When called by the Imac (newest), the "accept" or "reject" radio button appears for me to click and connect. On my wife's Ipad the two radio buttons always appear when a call actiivates Facetime and comes on?
    There is nothing I can find in "Preferences" in Facetime to turn that on or off. I suspect it has to do with having a more current operating system; that the "controls" are in the operating system? [I'm guessing] It's frustrating getting Facebook calls from several friends on Ipads! Any ideas...VFP

    I suspect it has to do with not having a more current operating system
    Exactly, what Apple is doing is leveraging new features only on newer OS X versions to force you to upgrade OS X to 10.7 or later.
    What they don't tell you is 10.7 or later will NOT run your PowerPC based software, some of it you can't get Intel versions like for perfectly working printers, scanners and games etc. So it can be a very expensive OS X upgrade to 10.7 or later with third party software.
    http://roaringapps.com/apps:table
    Also they don't tell you is the risk in bricking your machine if the update goes badly, so you have to have AppleCare in case that occurs so it's on them to fix it. Else your paying money to replace the logicboard or buying a new machine prematurely.
    A four year old machine can't have AppleCare, it's only good for 3 years from date of purchase new.
    Your machine came with a boot hard drive, it's usually got about 4-5 years of life on it, then it needs to be replaced.
    Also they don't tell you the newer OS X version has more abilities and features that causes your machine to slow down in performance, especially on older machines.
    Also they implement new, idotic and extremely fustrating new user interface features in a arbitrary "you take it or leave it" manner with little or no fall back method.
    So upgrading OS X is a gamble on older machines that otherwise would likely work perfectly fine for the next 5 years if one didn't need to have to mess with it.
    Since Snow Leopard has slightly over 25% OS X version market share, your still good for security updates etc for the next few years if you just want to stay where your at and be happy.
    OS X 10.4/10.5 need to upgrade, 10.6.8 ok still
    The Lions are, well, not so welcome due to Scott Forstall retard UI issues, OS X Mavericks 10.9 is likely going to fix things a bit better.
    But basically what is occuring is Apple is trying to force a faster hardware upgrade cycle with the more expensive products by leveraging features on the smaller devices that expire sooner.
    Apple is a hardware company that leverages whatever it can to get you to buy more hardware, it's why they are as rich as they are.

  • I want to buy music but i can't remember my security questions, It says to reset it but the link is not there to reset. It says to contact ap support but I've tried both ways to contact and it says it isn't working.

    I want to buy music but i can't remember my security questions, It says to reset it but the link is not there to reset. It says to contact ap support but I've tried both ways to contact and it says it isn't working.

    The reset link will only show if you have a rescue email address on your account (an alternate email address is different). If you don't have one (you won't be able to add one until you can answer your questions) then you will have to contact Support in your country to get the questions reset.
    How are you trying to contact Support ? You should be able to do so via the following :
    Contacting Apple about account security : Contact Apple for help with Apple ID account security
    Or if your country isn't on that page then use this form : https://ssl.apple.com/emea/support/itunes/contact.html
    When they've been reset you can then add a rescue email address for potential future use : Manage your Apple ID primary, rescue, alternate, and notification email addresses
    Or if it's available in your country you could change to 2-step verification : Frequently asked questions about two-step verification for Apple ID

  • When trying to sync my bookmarks etc to my new laptop (windows 8) it says it is synced but there is nothing on my new laptop. I did the code both ways

    I have a new laptop and numerous bookmarks I want to retreive from my desktop, I set up an account and paired the device both ways and its says synced but my laptop isn't showing the bookmarks or anything. Do you get the code from the old device and enter in the new device correct? again I did both ways because it didn't work so not sure what to do

    Thanks Amitshree
    I did go to those Links but again it's still not working so I need a little more assistance because although it says it is synced I see none of my bookmarks on my new laptop.

  • How to sync iCal with Google calendar (both ways)???

    I have been trying to sync my ical with my google calendar both ways.
    I got all new event created in google calendar syncing into iCal but i can't get the one created in iCal go into google calendar.
    Help please!!!!
    thx

    When entering a new event in iCal be sure your "google" calendar is highlighted on the left had side of your screen. That makes Google your default calendar as you add events. Or you can choose which calendar from the drop-down box in the details box when adding a new entry. The down side is that is seems you can only select one Calendar; so the "Home", "Work", "Untitled" options become moot if you want to sync back to google.
    If you already had events scheduled in iCal; you can right click on them, select "Calendar" and then choose your google calendar. When you refresh your google calendar that event should show up.
    You simply need to be sure what Calendar you're entering into. Also if you wait a few SECONDS the calendars DO sync without any need to manually synchronize them.
    So basically, ensure you're entering into the Google Calendar in iCal and wait a minute.

  • BB Desktop manager - sync not working both ways on new Tour

    Events from BB will sync with Mac but if I put an event in iCal it will not sync with the BB.
    Message: A SYNC ERROR OCCURRED. PLEASE RETRY SYNC during calendar sync
    Contacts will sync both ways 
    Computer: MACBOOK PRO 
    MAC OS X: VERSION 10.6.4
    BB Smartphone Tour 9630
    v5.0.0.624
    Desktop Manager software v1.0.4 (build 10) Currently says I am updated.
    Worked the first time, when desktop override smartphone selected and appeared to worked for a couple of days then I started getting this error.  I did initially check out all the syncing, with trial contacts and events and had no problems for those first few days.
    I tried to FORGET DEVICE.  Worked the first time, again when desktop override, but then stops working again and get same error message.
    Only change was that I added another email account to the phone (mobile me account).
    The main reason I went with BB over the other phones from my provider was to sync my calendars and contacts and now it is not working and I have only had the phone a week. So frustrated.
    Thanks,

    Hey raspes,
    Welcome to the BlackBerry Support Community Forums.
    When you're stating the BlackBerry Desktop Software is not able to find the calendar, do you mean it is not listed in the list of Calendars in BlackBerry Desktop manager?
    Have you tried forgetting the device and then re-attempting the synchronization?
    Go into Device>Forget Device.
    Once completed close BlackBerry Desktop Manager and re-open and it will ask you to re-setup the synchronization and all calendars should be listed now.
    -ViciousFerret
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Like! for those who have helped you.
    Click  Accept as Solution for posts that have solved your issue(s)!

  • How to guarantee two tables are in sync both ways on 10gR2?

    a table at x database and b table at y database are wanted to be in sync.
    if the request was in one way a dblink and a materialized view with refresh on commit would do the trick. but changes wanted to be replicated both ways, so I thought a trigger based solution but wanted to have your opinions if there is any clever trick for this kind of a need.
    Thank you.

    please correct me if I am wrong, by streams you meand async change data capture from redo logs right? In my opinion this is not easy to configure, and since these are two small parameter tables, so it will be throwing a rock to a frog?

  • TS3623 Apple TV works fine if connected directly to Samsung tv, but shows no or incompatible signal when connected through Harman Kardon AVR 1565 av receiver, other signals like dish satellite receiver work fine both ways

    Apple TV (1080p) works fine if connected directly to Samsung tv, but shows no or incompatible signal when connected through Harman Kardon AVR 1565 av receiver, other signals like dish satellite decoder work fine both ways.

    Does it help if you set the output to 720p.

  • I have a 5s which has been working fine until about a week ago when any calender event added to my phone will not sync with my enterprise server. Any calender event entered on my PC (enterprise) does show on my phone. Mail is working fine both ways,ideas?

    i have a 5s which has been working fine until about a week ago when any calender event added to my phone will not sync with my enterprise server. Any calender event entered on my PC (enterprise) does show on my phone. Mail is working fine both ways,ideas?Iphne 5s and enterprise

    See my reply to this message:
    https://discussions.apple.com/thread/2557520?start=15&tstart=0
    The problem is that the POP3 client is not issuing a DELE command to remove the email from the server.

Maybe you are looking for