[VPN] 837 + Netscreen

Henry Tham henrytham at aanet.com.au
Thu Jul 27 03:21:10 EDT 2006


Hi all,

Firstly, I am a newbie in the area of VPN. I have been experiencing problems
in creating a VPN tunnel from work.
I have an inbound NAT to the untrust (outside) interface of my Netscreen 5gt
firewall.

When connecting from the VPN client, the client is initiating with my
untrust interface which is a private address (192.168.0.x).

My first question is, must the VPN be terminated on a public IP? How do I
perform VPN passthrough? I have a NAT statement like this
ip nat source static 192.168.x.x interface dialer(x)

A simple network diagram:

Internet -> Cisco 837 (192.168.x.x /24)--> Untrust (Netscreen 5gt) --->
private network (172.16.x.x /24)

Thanks for your help.


Regards,
Henry Tham
 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.shmoo.com/pipermail/vpn/attachments/20060727/379f5b11/attachment.htm 


More information about the VPN mailing list