RE: OT: NAT and SNMP

From: Adam S. Roth (adam@therothfamily.net)
Date: Sat Dec 06 2008 - 12:29:01 ARST


Ezrick:

I thought there was issues when it used to traverse a PIX during
translation. Some other protocols has similar issues like SIP and you had
to do a fixup SIP on the PIX.

Thanks for your response.

Adam

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
ezrick dayan
Sent: Saturday, December 06, 2008 3:08 AM
To: Adam S. Roth; ccielab@groupstudy.com
Subject: Re: OT: NAT and SNMP

Hi Adam

Nat will be done only on the Trap Ip header.

SNMP trap include the source IP (pre-nat) in the snmp pay-load.

your network monitoring system should be configured to use one of these
IP's as the source.

good luck

Ezrick

<adam@therothfamily.net>
OT: NAT and SNMP

Hi:

I am working on a project with a VPN site to site. On one side of the
tunnel there is a PIX and on the inside interface a server collecting traps.
On the other side of the tunnel there is ASA with a layer 3 switch connected
to it. Connected to the Layer 3 switch on the inside there is a PIX or
router on doing static one to one NAT. The NAT translations on both sides
with the one to one NAT are RFC1918 addresses. Connected to the PIX or
router is a device sending traps. Will there be an issue with the network
monitoring platform being able to tell where the SNMP originated? Also, is
this considered double NAT because of the tunnel or is this a single NAT?

                          Site to site NAT 1 to 1
                           IPSEC RFC1918

[ Server/traps ]_____( PIX)- - -(ASA)____[L3 switch]______(PIX)---(SNMP)

Thanks

Adam

http://www.ccie.net



This archive was generated by hypermail 2.1.4 : Thu Jan 01 2009 - 12:53:07 ARST