Smart questions
Smart answers
Smart people
INTELLIGENT WORK FORUMS
FOR COMPUTER PROFESSIONALS

Member Login

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips now!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

Join Tek-Tips
*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

LINK TO THIS FORUM!

Add Stickiness To Your Site By Linking To This Professionally Managed Technical Forum.
Just copy and paste the
code below into your site.

Partner With Us!

"Best Of Breed" Forums Add Stickiness To Your Site
Partner Button
(Download This Button Today!)

Feedback

"...One of the best run forums I have used in years! ...I like the way the site is organized and your no tolerance of flames..."

Geography

Where in the world do Tek-Tips members come from?
fuseven (MIS)
14 Mar 12 15:13
Hello All,

First post, have always used this forum as a great reference to troubleshoot issues, now I have an issue worthy of posting.

As the subject states, I need to use public IP addresses as the Local Encryption Network for an IPSec VPN.

We have a small Public IP address block X.X.X.64 - X.X.X.79, and all are currently being used (NAT'd to).

I have been working on this for a while and I figure I need to make a small internal subnet (/29) out of the Public IP addresses, so X.X.X.72 - X.X.X.79

I can then define the X.X.X.72/29 subnet as the Local Encryption Network.  

Where I'm stuck is how to define the IPs coming from the DMZ to these addresses.  Since my Public IPs are in use, defining IPs as these Public IP addresses (Having local IPs translated to Public IPs that are already NAT'd to) is causing an overlap error.  Is there a way around this, or do I need to free up a couple Public IPs in order to NAT this information out?

Please let me know what you think and if any further clarification is needed.

Thank you in advance for the help!
E
SweetRevelation (TechnicalUser)
22 Mar 12 16:27
It's an interesting question, mine is why exactly do you need to use Public IPs?
fuseven (MIS)
23 Mar 12 9:28
haha, that's a great question and was my first to them.  Apparently that helps them keep tabs on which network is making the connection...I didn't really care for the explanation but what can you do?

So any thoughts on how to accomplish?

Thanks!
fuseven (MIS)
23 Mar 12 10:41
I already have the two needed IPs NAT'd to public IP addresses, so if I make an internal subnet of Public IPs (which will be my local network), that encompass the addresses that the DMZ IPs are already NAT'd to, in theory it should work?

I shouldn't have to specifically create a NAT entry from the DMZ to the Public IP with the Destination (the Remote Network) since it's already NAT'd as the IP to the outside interface.

I'm not sure I'm being clear but please have a read through and let me know what you think.

Thanks!

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members!

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close