In this scenario, your company wants to exchange sensitive data with one of it's business partners by using VPN. To further protect the privacy of your company's network structure, your company will also use VPN NAT to hide the private IP address of the system it uses to host the applications to which your business partner has access.
Suppose you are the network administrator for a small manufacturing company in Minneapolis. One of your business partners, a parts supplier in Chicago, wants to starting doing more of their business with your company over the Internet. It is critical that your company have the specific parts and quantities at the exact time it needs them, so the supplier needs to be aware of your company's inventory status and production schedules. Currently you handle this interaction manually, but you find it time consuming, expensive and even inaccurate at times, so you are more than willing to investigate your options.
Given the confidentiality and time-sensitive nature of the information you exchange, you decide to create a VPN between your supplier's network and your company's network. To further protect the privacy of your company's network structure, you decide you will need to hide the private IP address of the system that hosts the applications to which the supplier has access.
You can use VPN's to not only create the connection definitions on the VPN gateway in your company's network, but also to provide the address translation you need to hide your local private addresses. Unlike conventional network address translation (NAT), which changes the IP addresses in the security associations (SAs) that VPN requires to function, VPN NAT performs address translation before the SA validation by assigning an address to the connection when the connection starts.
The objectives of this scenario are to:
The following diagram illustrates the network characteristics of both the supplier network and the manufacturing network:
You must complete each of the following tasks to configure the connection described in this scenario:
Related concepts
Network address translation for VPN