Inside Source NAT from the remote host and VPN from Site to Site

Hi all

I was in charge of the construction of a vpn tunnel with a firewall PIX of our business partner company and ASA of the other company of the firewall.  Traffic will be A partner business users will access my company Citrix server.  I want to source-pat the user traffic partner company to PIX of my business within the interface to its entry in my LAN to access my company Citrix server.  The partner company will be PAT'ing their traffic from users to a single ip address - Let's say for discussion end is 65.99.100.101.  There is the site to site vpn configuration, and configure nat be performed to allow this traffic in accordance with the above provisions.

I'm more concerned about the accuracy of the configuration of the domain encryption because NAT is involved in this whole upward.  My goal is to NAT (of the other company company a) ip address to a routable ip address in my company network.

The fundamental question here is should I include the ip address of real source (65.99.100.101) of the company the user or IP natted (10.200.11.9) in the field of encryption.

In other words should the encryption field looks like this

OPTION A.

permit ip host 10.200.11.103 65.99.100.101

OR

OPTION B

permit ip host 10.200.11.103 10.200.11.9

I'm inclined to think it should look like OPTION A.  Here's the part of MY complete SOCIETY of the VPN configuration.  I've also attached a diagram illustrating this topology.

Thanks in advance,

Adil

CONFIG BELOW

------------------------------------------------

#################################################

Object-group Config:

#################################################

the COMPANY_A_NETWORK object-group network

Description company network access my company A firm Citrix

host of the object-Network 65.99.100.101

the MYCOMPANY_CITRIX_FARM object-group network

Description farm Citrix accessible Takata by Genpact

host of the object-Network 10.200.11.103

################################################

Config of encryption:

################################################

crypto ISAKMP policy 20

preshared authentication

3des encryption

sha hash

Group 2

life 86400

********************************

CRYPTO MAP

********************************

crypto Outside_map 561 card matches the address Outside_561_cryptomap

card crypto Outside_map 561 set peer 55.5.245.21

Outside_map 561 transform-set ESP-3DES-SHA crypto card game

********************************

TUNNEL GROUP

********************************

tunnel-group 55.5.245.21 type ipsec-l2l

IPSec-attributes tunnel-group 55.5.245.21

pre-shared-key * 55.5.245.21

*******************************

FIELD OF CRYPTO

*******************************

Outside_561_cryptomap list extended access permitted ip object-group MYCOMPANY_CITRIX_FARM-group of objects COMPANY_A_NETWORK

###########################################

NAT'ing

###########################################

Global (inside) 9 10.200.11.9

NAT (9 genpact_source_nat list of outdoor outdoor access)

genpact_source_nat list extended access permit ip host 65.99.100.101 all

genpact_source_nat list extended access permit ip host 65.99.100.102 all

! For not natting ip address of the Citrix server

Inside_nat0 list extended access permitted ip object-group MYCOMPANY_CITRIX_FARM-group of objects COMPANY_A_NETWORK

You must include pre - nat ip 65.99.x.x in your crypto-card, like you did.

For me, config you provided here looks good and meets your needs.

One thing, I do not see here the nat rule real 0, but there is the ACL that NAT. probably, you just forgot this rule.

65.99.100.101 #sthash.mQm0FIOM.dpuf

Tags: Cisco Security

Similar Questions

  • ICMP failed on inside the remote host by vpn

    A strange problem is then seen that he was working on an ipsec vpn on asa.

    ASA inside: 192.168.100.1 255.255.255.240

    host of the customer directly connected to ASA inside: 192.168.100.2

    tunnel to form properly. When the remote client 10.20.15.5 is crazy to asa, he answers.

    the same ping when tried customer 192.168.100.2 directly connected to the asa on the inside does not work.

    & This also does not bring the tunnel upward.

    of asa ping 192.168.100.1 & vice versa is very good.

    plotter configuration & race packet is attached. Ping between host traffic capture and asa inside the interface only displays not any what exit.

    Help, please.

    Thank you.

    That doesn't sound right.

    If it goes through the VPN tunnel, the traffic will be encrypted, and you shouldn't be able to see the break of your internet service provider.

    Can you please delete the xlate and connections to this host: disable 192.168.100.2 local

  • error on the remote desktop and VPN connections

    Unable to connect using desktop remote or VPN. remotes can't find the computer at home on the network and the VPN gives me an 800 error code. I used the remote desktop, but it says my work computer isn't on this network and the VPN connection fails. We checked everything using remote assistance, but it becomes too hard and not responses. Help!!!!!!!!!!!!!!!!!!!

    Hello

    Your question of Windows 7 is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public.
    Please post your question in the TechNet Windows XP category.
    Here is the link:
    http://social.technet.Microsoft.com/forums/en-us/itproxpsp/threads
     
    I hope this helps.
    Thank you, and in what concerns:
    Shekhar S - Microsoft technical support.

    Visit our Microsoft answers feedback Forum and let us know what you think.
    If this post can help solve your problem, please click the 'Mark as answer' or 'Useful' at the top of this message. Marking a post as answer, or relatively useful, you help others find the answer more quickly.

  • procedure for disconnecting the remote host?

    I'm currently updating my site by making a few changes to the photos that I use. The problem is that whenever I press the F12 key to show my page, he will live. that is I am connected to the remote host.

    In the files Panel, I'm looking at local View.I disconnect from the remote host, but if I do something, and then press F12 to control browser, it connects to the remote host again.

    Site > Manage Sites, select the existing site to open the Site Definition dialog box. Select the Advanced tab, and then select testing server from the category on the left column. Set access to zero.

  • change of page and go to the remote host

    I sent all my files to the remote host, but now I need to change a few things. I opened the page, I want to make a change from my local file. I made the change and it previews and it looks great. Now I can't figure out how to make so that it can change at the remote site. In the remote info from site management to maintain synchronization information are verified. Help, please. I'm so close how cela's site. I always test with the host country before I have it to point to the domain name. Thank you!!

    have you selected the file in the files Panel and clicked on SET?

    --
    Alan
    Adobe Community Expert, dreamweaver

    http://www.Adobe.com/communities/experts/

  • Existing connection had to be closed by the remote host

    Need help with this error
    I have a dev and a uat environment.
    I have a small form that I use as a method to call a web service. Essentially, the form contains a web service URL text box.
    If I call the shape on the dev and pointer to the service web dev, it works.
    If I use the form on uat and point the service web uat it works.
    If I use the form on UAT and call the web service on dev, it works.
    However, if I use the form on the dev and point the web service uat I get this error:

    In the Application Server error ' / '. An existing connection was to be closed by the remote host Description: An unhandled exception occurred during the execution of the current web request. Please review the stack trace for more information about the error and its origin in the code.

    Exception details: System.Net.Sockets.SocketException: An existing connection was to be closed by the remote host

    Source error:

    The source code that generated this unhandled exception can only be shown when compiled in debug mode. To do this, follow one of the below steps, then request the URL:

    1. Add a "Debug = true" directive at the top of the file that generated the error. Example:

    <%@ Page Language="C#" Debug="true" %>

    or:

    (2) add the following section to the configuration file of your application:


       
           
       

    Note that this second technique, all the files in an application to be compiled in debug mode. The first technique will make only this file to be compiled in debug mode.

    Important: Running applications in debug mode causes a memory/performance load. You must ensure that an application has debugging disabled before deploying to the production scenario.

    Stack trace:

    [(0 x 2746) SocketException: an existing connection was to be closed by the remote host] System.Net.Sockets.Socket.Receive (Byte [] buffer, Int32 offset, Int32 size, SocketFlags socketFlags) + 73 System.Net.Sockets.NetworkStream.Read (Byte [] buffer, Int32 offset, Int32 size) 131 [IOException: unable to read data from the transport connection: an existing connection was to be closed by the remote host.] System.Net.Sockets.NetworkStream.Read (Byte [] buffer, Int32 offset, Int32 size) + 294 System.Net.PooledStream.Read (Byte [] buffer, Int32 offset, Int32 size) + 26 System.Net.Connection.SyncRead (request of HttpWebRequest, Boolean userRetrievedStream, Boolean probeRead) + 297 [WebException: the underlying connection was closed: an unexpected error occurred during the reception.] System.Net.HttpWebRequest.GetResponse () + 5399741 _Default.btnTestUpload_Click (Object sender, EventArgs e) + 532 System.Web.UI.WebControls.Button.OnClick (EventArgs e) 111 System.Web.UI.WebControls.Button.RaisePostBackEvent(String eventArgument) + 110 System.Web.UI.WebControls.Button.System.Web.UI.IPostBackEventHandler.RaisePostBackEvent (String eventArgument) + 10 System.Web.UI.Page.RaisePostBackEvent (IPostBackEventHandler sourceControl, String eventArgument) + 13 System.Web.UI.Page.RaisePostBackEvent (NameValueCollection postData) + 36 System.Web.UI.Page.ProcessRequestMain (includeStagesBeforeAsyncPoint, Boolean, Boolean includeStagesAfterAsyncPoint) 1565

    Version information: Microsoft .NET Framework Version: 2.0.50727.4234; ASP.NET Version: 2.0.50727.4223

    Any ideas?

    Hello

    I suggest you for this post in the appropriate section of the form of MSDN

    http://social.msdn.Microsoft.com/forums/en-us/categories/

    I hope this helps.

  • An existing connection to be closed by the remote host.

    Since last week, I can't keep a connection to the server of vatsim or acars for virtual pilots micro flight simulator will for more than five minutes. the error message is that an existing connection had to be closed by the remote host

    not an expert of anymeans and all the answers I got on the net are well above my paygrade.

    Hi dva8377,

    Here are two additional methods you can try.

    1: Restart the computer by using a clean boot of the method

     

    When you start Microsoft Windows, other software may start with the operating system. These programs may include antivirus software and system programs that may interfere with the game. When you perform a clean restart procedure, you prevent these programs from starting automatically.

    Reference:

    How to troubleshoot a problem by performing a clean boot in Windows Vista or in Windows 7

    Method 2: Bypass the router

     

    If you connect to the Internet using a router, there may be a problem with the configuration settings, which requires that the updated settings. To determine if a network connectivity problem is caused by a bad configuration or a problem affecting the router, try bypassing the router by connecting your computer directly to the modem. Remember that this test will only check that the router is configured correctly. If the game connects to the Internet without problem when you bypass the router, plug the router immediately and contact the manufacturer of the router or your ISP for help configure the router correctly.

    Note: Ensure that you switch your computer to normal startup mode after completing the troubleshooting steps. Steps are available in the article above.

    For more information, see: http://www.microsoft.com/Products/Games/FSInsider/tips/Pages/default.aspx

    Kind regards

    Shinmila H - Microsoft Support

    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Copy Clone VM on the remote host?

    We currently have a Vcenter configuration limited to 3 guests.  I am creating a system for disaster, assuming that our main centre of recovery should fail.

    So, I need to program a clone of the VM are held every week - but then I need to copy this clone to a remote host which is not in the same data center, although it IS on the same network.

    Is there a way to achieve side manually remove a host to Vcenter and adding remote host (4th) whenever I want to copy?

    If I copy the clone on an external drive, I have to copy it again to the remote host.  It is 2 instances of copy on the network and which can last for hours.

    I want to reduce it to a single copy and perhaps even automate it with a script, but I don't know everything that the CLI in ESXi.

    Any ideas are appreciated.

    Understandable, I thought you wanted to just copy of VMDK but a clone first takes a snapshot of the virtual machine. This removes the lock on the base VMDK. ESXi can run rsync, but it is not supported. It is perhaps a bit over your head because you have no experience with Linux.

    http://www.virtuallyghetto.com/2011/02/how-to-compile-statically-linked-rsync.html

    What you could do is however if sure the source host and destination have access to the same storage. Then plan a clone to the virtual machine, but leave it turned off permanently. In the case of DR, on the other host, go to the data store, select the virtual machine folder, right-click the .vmx and say file added to the inventory. You can then restart it on another host. Or the DR host only has local storage?

  • On the remote host MySQL database: password encryption?

    Hello

    I discovered the world of PHP and MySQL in the last days. I didn't get all the intricacies still but nevertheless I managed to set up a server "localhost" on my computer, create a MySQL database and display correctly information in this database in HTML using PHP pages.

    I am now at the stage of transferring it to the remote host where the site will happen: I exported my database, imported these information in the database on the server host and I n unexpectedily even just to get my PHP/HTML pages to connect to this database. It's great.

    I have one question. I've read a lot of thread in this forum about this, but haven't seen an answer: must the password encryption? I mean, when I connect to a database using DW CS4, the software creates for me a connections folder in my Web site root folder and stores inside a little PHP to the folder with the server name, database name, user name and password which are necessary to allow PHP to connect to the MySQL database. It is all printed clearly in there. Once which is transferred to the remote host, it is always accessible to anyone? Should I not worry and try to hide the password?

    Any thoughts on this would be greatly appreciated.

    Emilie

    Thread moved to Dreamweaver application development forum, which addresses other issues aside and PHP/MySQL server.

    As long as the server is enabled in PHP, put the connection details in a PHP file like this is not a problem. PHP code is processed on the server. Only its output is sent to the browser. Even if someone guesses the name of your connection file, they won't see anything if they try to load the page in a browser. The only way they can see it is to hack into the server. It is important to have passwords on your FTP account.

  • The connection to the remote host has been lost.

    Seriously, almost every time I save a file and try to download it I get this error:

    The connection to the remote host has been lost. Click Refresh to reconnect.

    So I have to start again to download the file again... but no, I get this error again... until about 7 times then it will finally through. After that happening by once I have on a window of 2 minutes where I can download files without errors... then the cycle continues.

    This is driving me CRAZY! It happened for about 2 weeks. I have not recently changed all the server info. I used to download files on the same server from dreamweaver all the time with ease. My partner with the same configuration works always with ease. So why am I having so much trouble?

    I often have to troubleshoot PHP where I upload to the server to run it to see if it works, and I could have several times to download a file in the few minutes that becomes incredibly tedious task with this ongoing issue.

    Someone please help.

    Thank you!

    P.S. I'm using CS3.

    Ah ha! I finally got to work properly!

    Your site-> Site-> Remote Info Manager, try to check the passive FTP box and see if it works.

  • Unable to ping the remote host IP address

    I have a home network with 2 desktop computers, printer, TV and BlueRay attached.  The PC is both XP and members of the same workgroup.  I can't get the connectivity between the PC 2.  With 1 PC, I ping successfully all connected devices, with the exception of 2 PC.  2 PC, I ping equipment successfully connected, including 1 PC...  I get the same information using a different router and a different network on 2 PC card.

    I tried the following steps of the Article 314067:

    1. check on two PC's TCP/IP configuration.  Result: good on both PCs.

    2. use the ping tool to test connectivity.

    • Ping the loopback address.  Result: good on both PC
    • Ping to the IP address of the local computer.  Result: good on both PC
    • Ping the IP address of the default gateway.  Result: good on both PCs.
    • Ping to the IP address of the remote host.  Result: bad on PC 1, good on PC 2
    • Ping other IP addresses on the network.  Result: good on both PCs.
    • Ping the host name of the other PC.  Result: bad on PC 1, good on PC 2

    Article:

    If the ping command fails, the remote host may not be responding, or there may be a problem with the hardware of network between computers. To the rule

    on a remote host does not respond, use Ping again to a different remote host.

    If you cannot use Ping successfully at any time, verify the following configurations:

    1. Make sure that the IP address of the local computer is valid and that it is correct on the

    Tab general of the Internet Protocol (TCP/IP) properties dialog or box when it is used with the Ipconfig tool.  Result: good on both PC

    Make sure that the default gateway is configured and that the link between the host and the default gateway works. For the purposes of troubleshooting, make sure that this gateway by default is configured. You can configure multiple default gateways, gateways after the first gateway is used only if the IP stack determines that the original gateway is not working. Diagnosis is to determine the State of the first configured gateway. Therefore, you can delete all the other gateways to simplify your task.  Result: good on both PC
    Make sure that Internet Protocol security (IPSec) is not enabled. According to the IPSec policy, Ping packets may be blocked or may require security. For more information about IPSec, go to method 7: Verify Internet Protocol security (IPSec).  Result: good on both PC

    Thanks for your suggestions you may have.

    Hello

    Firewall such as Norton, McAfee etc can cause a loss of network connectivity, even when the network is correctly configured. Try disabling the firewall on both computers to see if the ping works.

    Tricky

  • Diagnostics network ping to the remote host, but has not received a response

    I'm trying to figure out if there is a problem with just my laptop not wanting to connect to a local free WiFi, so any help is appreciated. He worked two days ago only to stop abruptly last night.

    Windows Network Diagnostics comes back with the error message "Can not contact www.microsoft.com (65.55.12.249)" and "diagnostic network ping to the remote host, but has not received a response.

    The only repair option it evokes is ' reset NIC 'wireless network connection ' '.

    I can always connect to WiFi using my iPhone, and even a connected laptop computer work Companion. Yet once, if this can be fixed on my end, any help would be appreciated.

    Hello BrenJones,

    Thanks for posting back. DNS servers are controlled by your ISP. I communicate with your Internet service provider and confirm that you have the good DNS for your network.

    Hope this helps J

    Adam
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Error: This page cannot be displayed - the remote device and does not accept the connection. (! found)

    * Original title: this page cannot be display the remote or unit does not accept the connection. (! found)

    My internet connection works very well, I'm trying to access a page of my gate of the school we use to complete missions. I can access my web page of schools, I can access my e-mail from the school, but I can't get the e-portfolio page. It says cannot display this page - the remote device and does not accept the connection - (! found). He said to ensure that the TSL and SSL in the advanced internet options security part turned on who they are, my better protected as well the mode. I've never had a problem accessing this page before. It is only this page! Help!

    Hello Teresa,.

    The probable cause of this problem could be due to wrong settings for internet explore.

    Please see the link below, Windows 8, follow the steps to check the Proxy and DNS settings
    http://support.Microsoft.com/kb/956196/en-us

    Warning: Reset the Internet Explorer settings can reset security settings or privacy settings that you have added to the list of Trusted Sites. Reset the Internet Explorer settings can also reset parental control settings. We recommend that you note these sites before you use the reset Internet Explorer settings.

    Hope this helps, please answer with the results for assistance.

  • Unable to connect to the MKS: the certificate of the remote host has these problems:

    Hello

    We have a host of ESXi 4 cluster running any vSphere 4.1.  Recently, I started to upgrade to update 2 and all the additional fixes.  After the upgrade of the vCentre server to the latest version (or maybe before I can't noticed) an of are hosts began to show the following error whenever I tried to connect to the console of any guest on this host.

    Unable to connect to the MKS: the certificate of the remote host has these problems:

    It lists any problems at all and no error display in the event log that it simply does not work.  I had a prod around the internet and found nothing.  I then rebuilt the host to exclude and the problem remains.

    Any help would be much appreciated.

    Thanks in advance

    David

    If you can connect to the Console remotely using VMware Infrastructure (VI) Client connected directly to the host, take a look at vmware KB to connect to a remote virtual machine fails with the error: the certificate of the remote host has these problems

    but more generally - remove host to vCenter inventory and then add the host to the back, take a look at opening in the console of the virtual machine after a new installation of ESXi or ESX fails with the error: the host certificate chain is not complete and could not connect to the MKS: the certificate of the remote host has these problems

  • Error during communication with the remote host when you create the new virtual machine

    I'm under 7 ESX servers on IBM Blade H22 there is a mistake to invite while I create a new virtual machine

    on the vcenter Server

    At the end of 30-35 minutes, it gives an error

    "Error during communication with the remote host"

    The existing machines are working well... I tried to create virtual machines to other ESX servers as well

    but the same question. I also tried to make the clone of existing machines, but without success

    Can anyone help?

    You rescan the LUNS once?

    You've restarted the management agent?

    You've restarted the vpxa?

    If this isn't the case, please perform the step above and check out them.

Maybe you are looking for