Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Cisco/Sonicwall 3DES through NAT?

0 views
Skip to first unread message

Kelly McCubbin

unread,
Jun 7, 2001, 12:50:34 PM6/7/01
to
Hi. I'm wondering if anyone can give me some pointers on this...
In my office I have a Cisco 2611 running Source NAT to the Internet.
At a remote office I am running a Sonicwall with VPN capabilities which will
handle 3DES encryption.
I need to connect a VPN tunnel between the two and have to, for other
reasons, do it as 3DES.
If I buy an IOS add-on pack for IPSEC (And if anyone knows exactly which
one, that'd be helpful too!) for the Cisco Router, will I have any problems
a)because of the NAT? and b)because it's Cisco to Sonicwall?
Thanks for any and all advice,

- Kelly (kmcc...@photoalley.com)

Harry

unread,
Jun 7, 2001, 3:03:03 PM6/7/01
to
The best code to use I in my opinion is 12.1(3xg-1,2or3)

Nat can be configured so that it does not interfere with the "protected
networks", but if you have to nat the vpn traffic as well, then you have to
configure particular transforms.

There is a white paper PDF on how to connect Sonicwall to IOS, if the link
does not work I can e-mail it.

http://www.sonicwall.com/vpn-center/vpn-setup.html


Steven Griffin

unread,
Jun 7, 2001, 4:45:37 PM6/7/01
to
If you have a Cisco PIX firewall, the IPSec termination is much easier. The
PIX can be configured such that it does not NAT the incoming IP traffic.

"Kelly McCubbin" <kmcc...@photoalley.com> wrote in message
news:uhOT6.20$796....@news.pacbell.net...

Keith A. Pachulski

unread,
Jun 11, 2001, 9:24:04 AM6/11/01
to
Sonicwall to IOS VPN Terminator

ftp://ftp.sonicwall.com/pub/info/IKE%20-%20Cisco%20IOS-PIX%20Interop%20with%20SonicWALL.pdf

any cisco IOS image supporting IPSEC is okay be it 12.0, 12.1, or 12.2

-keith

Kelly McCubbin

unread,
Jun 11, 2001, 2:09:54 PM6/11/01
to
Thanks for this link, both of you. I tried it exactly as typed (with my
IP's and password, of course) and got nothing. No connection at all. I
tried tracing from both sides and the addresses failed as soon as they tried
to get onto the public internet which says to me that the tunnel is not
being created.
I have a few thoughts...
1) The NAT on the Cisco side is converting the addresses before they get to
the VPN instructions and therefore not being wrapped up.
2) The Firewall rules need to allow ports other than TCP 50 and 51 and UDP
500.

Any ideas?

- Kelly (kmcc...@photoalley.com)

"Keith A. Pachulski" <kei...@corp.ptd.net> wrote in message
news:3b24c3db...@news.ptd.net...

0 new messages