ip nat inside source route-map nonat interface GigabitEthernet0/1 overload
!
route-map nonat permit 12
match ip address NONAT
!
!
ip access-list extended NONAT
deny ip 10.10.10.0 0.0.0.255 10.10.11.0 0.0.0.255 (deny NaTing across the link via ipsec vpn)
permit ip 10.10.10.0 0.0.0.255 any
Comments
(There are currently no comments for this post.)