8-75
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter8 Site-to-Site VPN
How Do I...
How Do I Configure a VPN After I Have Configured a Firewall?
In order for a VPN to function with a firewall in place, the firewall must be
configured to permit traffic between the local and remote peer IP addresses. SDM
creates this configuration by default when you configure a VPN co nfiguration
after you have already configured a firewall.
How Do I Configure NAT Passthrough for a VPN?
If you are using NAT to translate addresses from networks outside your own and
if you are also connecting to a specific site outside your network via a VPN, you
must configure NAT passthrough for your VPN connection, so that network
address translation does not take place on the VPN traffic. If you have already
configured NAT on your router and are now configuring a new VPN connection
using SDM, you will receive a warning message informing you that SDM wi ll
configure NAT so that it does not translate VPN traffic. You must accept the
message so that SDM will create the necessary ACLs to protect your VPN traffic
from translation.
If you are configuring NAT using SDM and you have already configured a VPN
connection, perform the following procedure to create ACLs.
Step1 From the left frame, select Additional Tasks/ACL Editor.
Step2 In the Rules tree, choose Access Rules.
Step3 Click Add.
The Add a Rule dialog box appears.
Step4 In the Name/Number field, enter a unique name or number for the new rule.
Step5 From the Type field, choose Extended Rule.
Step6 In the Description field, enter a short description of the new rule.
Step7 Click Add.
The Add a Standard Rule Entry dialog box appears.
Step8 In the Action field, choose Permit.
Step9 In the Source Host/Network group, from the Type field, select A Network .