Overlapping address space question - how to NAT inside the traffic to one address different range on SAA for comms with 3rd party VPN?

We already have a connectivity of IPSEC VPN site to site with a 3rd party.

They must be able to access a couple of servers on our internal network but the problem, it's the subnet these servers are hosted on clashes with the address space they already used elsewhere. Thus, they asked if we can put in place a new subnet and have our firewall (running v7.2) ASA NAT the traffic to and from our servers ' real' internal addresses.

for example

  • 3rd party 10.10.10.0/24 subnet
  • Our subnet 10.20.20.0/24 (but this clashes with the 3rd part of the address elsewhwere space)
  • Our 'real' internal server addresses are 10.20.20.1 and 10.20.20.2

How do we setup NAT on our ASA translating internal addresses 'real' of these servers for some other addresses that don't clash?

that is that the 3rd party is concerned, they would simply have to communicate with this 'new' subnet, say, 192.168.20.0/24 and our ASA firewall NAT traffic accordingly to allow some comms unfold?

(And it should affect only comms on these servers for the 3rd party - NOT for one of our other multiple VPN connections! "And should not affect the other comms from the servers themselves!).

That's what I've tried so far, for one of the servers, without success:

On ASA:

!

access-list 1 permit line 3rdpartysite extended ip host 192.168.20.1 10.10.10.0 255.255.255.0
!
access-list SERVER-NAT line 1 permit extended ip host 10.20.20.1 10.10.10.0 255.255.255.0
!
static (inside, outside) 192.168.20.1 public - access NAT SERVER list

"sh xlate" indicates:

192.168.20.1 global local 10.20.20.1

Can someone help with the necessary NAT configurations on the ASA?

Thank you!

'Clear xlate' after you have configured NAT statements?

When you try to ping from the 10.20.20.1, get it to the ASA? You have an ACL on this interface that would block the ping? Also, can you run capture packets on the ASA to see if the ASA receives even the traffic?

What is the subnet mask of the 10.20.20.1 host? I guess it's 255.255.255.0?

You don't need something specific on the ASA with regard to the delivery of the 192.168.20.1.

Tags: Cisco Security

Similar Questions

  • I'm 'in the Community' (or I couldn't ask a question) how can I get the PW I put here?

    I'm 'in the Community' (or I couldn't ask a question) how can I get the PW I put here?

    I know it may seem silly for a computer "geek" to not write it down but... @ 81 Alheimers rules!

    Cescokid

    Hello

    Use the links below to reset your Windows Live ID password:

    http://windowslivehelp.com/solution.aspx?SolutionID=6ea0c7b3-1473-4176-b03f-145b951dcb41

    https://windowslivehelp.com/PasswordReset.aspx

    If you need assistance, you will need to create a post on www.windowslivehelp.com

  • How can I make the menu title of a different color when it is horizontal Spry menu menu?

    How can I make the menu title of a different color when it is horizontal Spry menu menu?

    Dreamweaver CS5.5

    Apple OS X.6.8

    Display of the site to: http://Dorsay-Easton-Indian-law.com/staging/index.html

    Steps to follow:

    1. click on the link to land on the home page

    2 link see Home in the Spry horizontal navigation menu

    Real:

    Title of the home menu is the same color as all the others.

    Expected:

    The title of the active menu is color: #FFC.

    I was hoping that a: active would give me this feature, but it's not how it is described. All suggestions are welcome!

    The tag BODY nothing that I tried in the editable model. This is why I wonder how to disconnect the model individual pages. Adding an ID to each body tag is a condition sine qua non of the how-to page that you provided.

    You are not theeditable in a template tag.

    You are the attributes of theeditable tag.

    Do not unplug the model child pages.

    Specify editable tag attributes in a template

    http://help.Adobe.com/en_US/Dreamweaver/CS/using/WScbb6b82af5544594822510a94ae8d65-7aa3a.h tml

    In the model:

    1. Select ittag (in the tag selector, or click inside the)tag in Code view)
    2. Modify > templates > make attribute editable
    3. Select the code in the drop down attribute
    4. If there is no ID attribute then click Add and type the ID in the next dialog box
    5. Attribute: ID
      Check the box 'Make attribute editable '.
      Enter anything in the field of the default label for example foo
      Ok
    6. Dreamweaver will change thetag to read
    7. The ID is now editable
    8. Save the model and update the child page

    In each page of the child:

    1. Edit > properties of the model
    2. Select the id attribute in the list (it's probably the only one listed)
    3. Change its name in the box to any name matches your CSS rule for the active state of the page
    4. Ok
    5. Save
    6. Download
  • How can I chage the direction of one of my extended in MS XP desktop monitors

    How can I chage the direction of one of my extended in MS XP desktop monitors

    In your notifications area, right-click on the icon for your graphics driver. Since I did not lnow what grapiics driver you have, I can't help you much here. However, this will give you many settings and menus that should include one to change the orientation of a specific moniter.

  • How can I change the duration of an MP3 file I downloaded? For example, I have a song that 1.5 last minute, but I want to only keep the 21 seconds. How can I culture there?

    How can I change the duration of an MP3 file I downloaded? For example, I have a song that 1.5 last minute, but I want to only keep the 21 seconds. How can I culture there?

    Your best bet would be looking for writers to mp3/wave. There are a few very good freeware/shareware sound there. I suggest this so that you can choose what format you want to save your file cropped as.

  • Do you know what does DPI mean? How can I increase the resolution of a TIFF image at 300 DPI for shipment to a Publisher?

    Is anyone here know what DPI?  How can I increase the resolution of a TIFF image at 300 DPI for shipment to a Publisher?

    If the resolution is already less than 300, may not increase to make it higher. You can only do low.

    =====================================
    Yes, you can increase the DPI value.

  • How can I chang the language from one to the other?

    How can I chang the language from one to the other?

    Change the language of Adobe Creative Cloud applications

  • How can I reinstall the Photoshop from one computer to another? I didn't need a second license...

    How can I reinstall the Photoshop from one computer to another? I didn't need a second license...

    You are allowed to install Photoshop on two computers. Recent versions allow to choose if they are versions Mac or Windows, or one of each!

  • How to make all the fields on one page read only (for the recipient) without having to make each field read-only?

    How to make all the fields on one page read only (for the recipient) without having to make each field read-only?

    Hello Jmbtexas4,

    By default, you will need to individually click on the fields of the form and check the 'read only' and save it. From now on, it is not possible to select all together and make the changes.

    -Usman

  • The font size in the menu bar is too small (illegible). How can I increase the font size. I have a new Samsung PC screen with high resolution.

    Hi the TPN of size in the menu bar is too small (illegible). How can I increase the font size. I have a new Samsung PC screen with high resolution.

    What version?

  • Page layout question: have 2 box inside the splitter facet

    Hi guru

    I need to have 2 Cabinet stacked vertically within the 2nd side of a separator (vertical) Panel and have a vertical scroll bar to scroll through the entire space of the 2nd facet. In addition, the Panel box #2 should move upward when the Panel box #1 is reduced. How to get there?

    I tried this

    < af:panelSplitter orientation = "vertical" >
    -< f: facet = 'first' name >
    -stuff inside the first facet
    -< / facet >

    -< f: facet 'second' = name >
    -PanelGroupLayout scroll >
    -< PanelBox 1 >
    -The things inside the box
    -< / PanelBox 1 >

    -< PanelBox 2 >
    -< PanelCollection >
    ----------------------------------<Table>
    ----------------------------------</Table>
    -< / PanelCollection >
    -< / PanelBox 2 >
    -< / PanelGroupLayout >
    -< / facet >
    < / af:PanelSplitter >

    The above provision extends from the first Panel area to the entire width of the screen, but the 2nd box is extended to only 50% of the width. I also modified the above to have the two boxes to Panel within a presentation of form of Panel with lines = '2' and argument maxColumns = '1 '. With that, the two panel boxes are stretched until 50% of the width of the screen. The problem is due to the table inside the box # 2 Panel?

    Help, please.

    Thank you

    Published by: user12612448 on January 4, 2011 04:10

    Hello

    A panelGrouplayout can be stretched in a panelsplitter until the layout is set to scroll or vertical.
    So it of ok and should work in your case

    A panelBox can be extended, however, it will not stretch her children, while the panelCollection will not stretch.
    Indeed, if it is caused by the content of the second panelbox.

    Try to use a styleClass to stretch the panelCollection example styleClass = "AFStretchWidth."

    Good luck

    Luc Bors

  • How can I create a network and put in on my iphone 4S for use with wifi?

    I have a phone, a personal hot spot 4s, a router and a broadband cable. Everything is running but I can't figure out how to get my network on my iPhone for use with Wifi.  Also, I don't know how or where on the phone to set the password and since I don't have a different password, I can't use my wifi?  Help, please!  My iPhone tech is exhausted and I'm going against a brick wall with my internet service who refuses to provide me with their ISP, etc.

    Hello

    Please ask your question the following support forums.

    iPhone: Apple Support communities:
    https://discussions.Apple.com/community/iPhone?CategoryID=201

    Concerning

  • Windows Server 2008 R2, with two Windows Storage Server 2003 Standard: How can I add the MAC authentication on top of Active Directory authentication for a storage servers?

    I have two running Windows Storage Server 2003 storage servers in a domain R2 Windows Server 2008 Standard.  On top of the Active Directory authentication, I want to add authentication of MAC address for the access to one of the storage servers.  In this scenario, an authenticated user is unable to log on to the target storage server unless the user is also on one of the computers MAC address accepted.  All domain users will have access to other folders and files as configuration storage server in Active Directory.  I already have a user access to installation by the permissions for folders on the storage server target, but I still want to restrict access to specific computers as well.  For what it's worth the server hardware is HP Proliant DL360 G5 for the Standard Server 2008 R2 and server HP Proliant DL185 G5 for two Storage Server 2003 computers.  I don't want to have MAC address authentication as the main means of access control to the network, only for the storage server a as an addition to control Active Directory.

    Hi Kerry,

    The question you posted would be better suited in the TechNet Server Forums since we have dedicated to this support; We recommend that you post your question in the TechNet Forums to get help:

    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

    Keep us informed on the status of the issue.

  • How can I activate the 20 GB of additional server on creative cloud for my team?

    How can I activate the 20 GB of space on the server that is supposed to come with my business team 3 Member?  I have 2 GB and the seller on an appeal after having been informed of call sales support person gave instructions to go to help on the management page, but there is no position about space on the server from anywhere.

    It has no adjustment in the creative cloud for portal teams to change the amount of storage allocated to your account.

    If you bought it, then the storage must be available automatically. To see it, you will need to disconnect and reconnect to cloud creative from within your application.

    Manage your cloud of Adobe Creative for the composition of teams

  • How can I get the tabs colorful to use different distinct colors for 2 gmail accounts?

    Under Firefox 29.0.1 iMac OSX 10.9.3. I have multiple Google accounts: 2 1 Google Calendar and gmail accounts. Colorful tabs add-on will allow me to choose a color for a gmail account, but it also uses this same color for the other gmail account. How can I get the different colors on 2 gmail accounts?

    In addition, colorful tabs is also the same for my homepage (google.com) and my google calendar. How can I get different colors on these 2?

    Personally, I use 'Fabtabs' for my mozilla FireFox.

    https://addons.Mozilla.org/en-us/Firefox/addon/FabTabs/

    This add-on has problems like that when I use it.

Maybe you are looking for

  • Why doesn't my password work?

    I signed up for an account in the last 30 minutes. I chose a password and confirmed. Then I went to the Android store to download Firefox for Android on my phone - and it has worked successfully. But when I tried to login, my password was rejected. I

  • iPad password update

    Hello. air iPad raises for the access code after update. No password has been set up on the iPad. Full keyboard pop up is terminoligy change? He is looking for Apple ID? Trying to help my elderly mother remotely.

  • How long is the battery on the Satellite A100-813 work time

    HelloCould you please tell me battery time of this model?For the moment I can use only for max 3 hours, is that correct?

  • HP PAVILION NOTEBOOK 17-g000nv: accelerometer for windows 10 pilots

    I have the HP PAVILION NOTEBOOK g000nv 17. I do not see my accelerometer in nowhere Device Manager, and looks to does not work. Please guide me to solve the problem or perhaps install new drivers for windows 10. Thank you

  • Analog clarifying not adjusted read API

    I use a USB-6009 box, and I will read the data to integer out of the device using the API C of NOR-DAQmx.  I understand that bypasses implementing scaling and offset that is applied when the bed is floating point. Ideally, I would like to read signed