Hey guys, our IT department has a problem which we're trying to figure out for a while now.
We've got a site-to-site IPsec tunnel connecting our business partner's infrastructure with ours. The tunnel works fine but the problem is translating 'external' subnets 'into the tunnel'.
I'm not sure I'll be able to explain it correctly so I'm attaching a simple diagram.
What we want to achieve is to translate traffic from network 10.0.3.0/24 to our business partner's side - 172.17.1.0/24. It seemed quite simple in theory but we're not able to make it work. We tried many, many different things but still... no success. We can't connect those networks directly (another Phase 2 or another IPsec tunnel @ 10.10.0.3) - it must be done through the tunnel @ 10.10.0.45.
The weird thing is traffic reaches our partner's side. We can get a response from...