ER605 source nat on ipsec

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

ER605 source nat on ipsec

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
ER605 source nat on ipsec
ER605 source nat on ipsec
2024-02-20 10:44:16
Model: ER605 (TL-R605)  
Hardware Version:
Firmware Version:

hello,

 

I'd like to use a ER605 in a remote site to terminate a site-2-site ipsec VPN.

 

is it possible to install a ER605 in one-leg configuration and to do source ip nat on the internal network ip address?

Explaining better:
- I already have a firewall on site A (static public ip on the firewall)
- I already have a consumer router on site B (static public ip, internal ip 192.168.123.1/24 and nat to allow internal network 192.168.123.0/24 to reach internet)

- I'd like to install ER605 inside the network on site B with ip address 192.168.123.2 and gw 192.168.123.1 and ip forwarding on the router to forward ipsec (udp/500, esp and ah) from the public ip to the internal ip of the ER605)

- I need a site-2-site ipsec from firewall on site A to the ER605 on site B

- I want the ER605 to to source nat (on ip 192.168.123.2) for packets arriving from the ipsec and destination hosts on the 192.168.123.0/24 network)

 

I think all is ok, but I don't know if the ER605 is able to make the source nat (as I don't want to change default gw of the hosts on 192.168.123.0/24 network I need to contact from the ipsec) on the same interface where ipsec came in.

 

thanks

  0      
  0      
#1
Options
1 Reply
Re:ER605 source nat on ipsec
2024-02-21 02:08:27

Hi @x-point 

Thanks for posting in our business forum.

You CAN port forward on B router and forward ER605 WAN 192.168.123.2. And ER605 LAN is NOT possible to interact with the 192.168.123.1/24.

 

I am not sure what you want, if the above reply does not answer your question, please get a diagram and show me what you need.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#2
Options