CourtLNet36
IS-IT--Management
Please excuse my ignorance on these subjects but I'm curious for an answer.
Here is the layout. We have a system being installed into a customer site. Our system is somewhat stand-alone and has it's own firewall. Typically we have VPNs up between that system and our network. However this location is different than others in that the Untrusted side of our firewall will be NAT'd through the customer's 2600, which is their only access point. I'm not sure which type of IOS they are running. I'm pretty sure there will still be a single, separate public IP assigned to us, i.e. the Untrusted interface won't resolve with the same public as all the rest of the hosts in their network.
What I need to know is, will IPSec traffic still pass through their 2600 to allow us to complete the VPN connection to our firewall? Does the 2600 care about the IP protocol? We have had our Untrusted NAT'd before, but that was behind another firewall and the only thing that needed to be done was have the customer assign the appropriate IP protocol to the NAT.
Thanks in advance!
Here is the layout. We have a system being installed into a customer site. Our system is somewhat stand-alone and has it's own firewall. Typically we have VPNs up between that system and our network. However this location is different than others in that the Untrusted side of our firewall will be NAT'd through the customer's 2600, which is their only access point. I'm not sure which type of IOS they are running. I'm pretty sure there will still be a single, separate public IP assigned to us, i.e. the Untrusted interface won't resolve with the same public as all the rest of the hosts in their network.
What I need to know is, will IPSec traffic still pass through their 2600 to allow us to complete the VPN connection to our firewall? Does the 2600 care about the IP protocol? We have had our Untrusted NAT'd before, but that was behind another firewall and the only thing that needed to be done was have the customer assign the appropriate IP protocol to the NAT.
Thanks in advance!