rossonieri#1 wrote: ya - i know its PBR. true a DIP can be one IP in your tunnel sbnet - but still the PIX see it as 2 IPs want to connect to it right? 1 is the tunnel itself, and 1 for the PAT-ed client. so the workaround is to : create ip unnumbered loX - use it for both DIP and tunnel interface. never tried that - but it should work. just my opinion. HTH.
Screenie wrote: Nating in in a tunnel can be done. I did iit between a net screen and a MS VPN server. First define a numbered tunnel interface, unnumbred won't work! Then define a policy with nat src behind interface. Third overrule your proxy-id in phase II settings with your int ip adres, 32 bits. Should work. Goof luck, Screenie.