Skip to main content
madra29
New Member
May 13, 2025
Question

Internal IP forward to a different IP

  • May 13, 2025
  • 1 reply
  • 352 views

I have an unusual issue that I have to get resolved.

I have a vendor that connects to our Internal IP - call it 10.1.1.1 via policy based vpn tunnel strongswan. That tunnel needs to reach 10.2.2.2 which is on a different VPN tunnel. routes are in place to get that traffic, but the vendor side can't make routes.

Incessance, they want to be able to connect to 10.1.1.50 on their end, and have our end pass that traffic being sent to that IP to 10.2.2.50 on our end. The vendors end has no idea 10.2.2.50 exists. all traffic will need to be translated. I am trying to figure out if a NAT will do that, or if there is a different way?

It will be internal to basically internal forwarding. Or is this not possible?

1 reply

funkylicious
SuperUser
SuperUser
May 13, 2025

DNAT will do the job in your case, just make sure that isnt not being used/assign anywhere else.

just make sure that there's a return route for the traffic on 10.2.2.x end or SNAT the traffic of your vendor towards 10.1.1.50>10.2.2.50

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!