pogue wrote: » If you have two private networks that need to communicate over an IPSec tunnel, how do you handle the individual computers/servers that have static NATing configured? By the behavior I am seeing in GNS3, it looks like these systems get NAT'ed regardless due to the static NAT mapping, and will ignore any NAT access list that attempts to prevent the address from being NATed.
networker050184 wrote: » This may clear it up a bit.NAT Order of Operation - Cisco Systems
pogue wrote: » wave, I have been able to ping 10.10.10.1 the entire time.. It is only pinging 10.10.20.238 that does not work, as it appears that the static NAT entry forces the NATing before the NAT ACL can deny it. Does your configuration allow you to ping 10.10.20.238?