PIX VPN Inside NAT'ing question

MysticLlama

Golden Member
Sep 19, 2000
1,003
0
0
I know there are a few people around here good with PIXs , and I'm working on getting there.

I have my head unit and multiple tunnels going now, and I want to start on another project, but I'm not sure if it is possible, or if I'm just looking at doing it the total wrong way for what I want to accomplish.

Right now our ERP provider has full access to our network because in the beginning they set up the Linux gateway server, sendmail on that server, all of our network addressing, etc. They basically built all of what was here before I got here.

Since I've been here there is a Windows domain, DHCP, internal DNS, a new mail server, a PIX firewall, and several other new things.

The Linux server is now not being used for anything except their access, but it's got so many services running on it that I don't want to deal with it as a risk just for their comfort.

I was thinking about just buying a PIX501 for their office that they could use as a gateway to our network, but this presents two problems.

1.) Since they set up our network in the first place, in all of their wisdom they set it up with the same range as their own, so if they are connected the IPs will crash into each other.

2.) I'd really like to take this opportunity to not allow them to have access to every computer in our network, they have no need to get into our storage server, other databases, intranet, etc., and while I have them disallowed from this stuff I still just don't like it. (They are very bad at just poking around and getting into things when they are supposed to be doing other stuff).

What I'd like to know is if it's possible to use NAT somehow to basically only make the three machines they have access to have numbers in their range on their network. This keeps me from renumbering everything (which will happen eventually, but I'm putting it off), and also keeps them from getting into stuff that they shouldn't be messing with because it won't have a mapping.

Is this possible? If it is I'll start trying to figure out how to do it, but if it's not, I'd rather not bang my head against the wall on it.

Or... am I just going about allowing access to them in the wrong way? Is there an easier way to do it?

I was thinking ACLs for just those IPs, but they crash into the IPs on their network, so that won't work for them to access stuff, there has to be some sort of NAT involved.
 

Shadow07

Golden Member
Oct 3, 2000
1,200
0
0
You would configure a NAT rule that would look like this:

nat (inside) 1 x.x.x.x 255.255.255.0 access-list 101

You would then have an access list defined for 101 that would allow internal traffic to the private side of the VPN tunnel. Then you would build your IPSec tunnel for both sides.

I got some of the info from here.

I might be wrong on this one, but I'm pretty sure I'm close and others will correct me.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |