Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    NAT external subnet through IPsec tunnel

    Scheduled Pinned Locked Moved IPsec
    1 Posts 1 Posters 270 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NetcrockN
      Netcrock
      last edited by

      Hey guys, our IT department has a problem which we're trying to figure out for a while now.

      We've got a site-to-site IPsec tunnel connecting our business partner's infrastructure with ours. The tunnel works fine but the problem is translating 'external' subnets 'into the tunnel'.

      I'm not sure I'll be able to explain it correctly so I'm attaching a simple diagram.
      What we want to achieve is to translate traffic from network 10.0.3.0/24 to our business partner's side - 172.17.1.0/24. It seemed quite simple in theory but we're not able to make it work. We tried many, many different things but still... no success. We can't connect those networks directly (another Phase 2 or another IPsec tunnel @ 10.10.0.3) - it must be done through the tunnel @ 10.10.0.45.

      Maye somebody here had some luck with similar problem or will be able to advise something?
      I can provide any details required if someone is willing to help.

      NAT_IPsec_problem.png

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.