Quantcast
Channel: SRX Services Gateway topics
Viewing all articles
Browse latest Browse all 3959

How to apply NAT before policy based IPSEC VPN? Virtual router an option?

$
0
0

 

Hi all,

 

have an issue.

Need to set up an IPSEC VPN from Juniper SRX 240  to a third party, running PFSense firewall.

 

LAN subnet on my end is 10.0.0.0/24

The requirement is to have it NAT-ed (source NAT, dynamic ports) to 172.16.1.1/32 before sending into the IPSEC tunnel.

LAN subnet behind the remote PFSense is 192.168.1.0/24

 

I was wondering if I could create a virtual router, use it just for the purpose of NAT, and once NAT is done, to send it to current router?

 

The sequence should look like this:

10.0.0.0/24 -NAT- > 172.16.1.1/32 ->IPSEC tunnel -> 192.168.1.0/24

 

Thanks for your time!

 

Cheers,

 

Alex

 

 


Viewing all articles
Browse latest Browse all 3959

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>