Mobile IPSEC IKEv2 NAT to Site to Site IPSEC?



  • Not sure if this is possible but I'm trying to allow Mobile IPSEC clients to NAT to an existing LAN on site A before going out a Site to Site IPSEC tunnel to Site B.

    Site A is our site
    Site B is a Vendor site
    Mobile clients not permitted to connect directly to Site B

    Here is the existing tunnel:
    Site A to Site B IPSEC
    172.30.140.0/24 <-> 10.25.0.0/24

    Mobile IKEv2 Clients IP: 192.168.142.0/24

    Is it possible to have the mobile clients connect to Site A, then onto Site B with a NATed address of 172.30.140.x??