<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,No , NAT exemption wouldn in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700069#M190950</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;No , NAT exemption wouldn't help with that.&lt;/P&gt;&lt;P&gt;You can check this document about the trace route and how it works on ASA device:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html#trace&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jun 2015 08:17:40 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-06-05T08:17:40Z</dc:date>
    <item>
      <title>ASA 8.0 nat0 statement problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700066#M190947</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA is working on&amp;nbsp;8.0 and I would like to bypass NAT which from 10.131.3.0 to 10.130.8.0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Refer to nat0 document, it is clearly stated that nat0 is worked for bypassing NAT. However, I want to clarify, refer to below configuration, if nat0 statement works, does it refer to the routing table (route inside 10.0.0.0 255.0.0.0 10.131.3.1) to next hop ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;==========================================================&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;nat (inside) 1 10.0.0.0 255.0.0.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip 10.131.3.0 255.255.255.0 10.130.8.0&amp;nbsp;255.255.255.0&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 203.221.172.210 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.131.3.1 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:03:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700066#M190947</guid>
      <dc:creator>Kurt Lei</dc:creator>
      <dc:date>2019-03-12T06:03:16Z</dc:date>
    </item>
    <item>
      <title>Hi,Just to clarify , the NAT</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700067#M190948</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Just to clarify , the NAT and route lookup and different phases of a packet on the ASA device.&lt;/P&gt;&lt;P&gt;So , yes the ASA would have to look at the routing table in order to pass the traffic in addition to the Nat Exempt statement.&lt;/P&gt;&lt;P&gt;Packet Flow thru ASA:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/113396-asa-packet-flow-00.html&lt;/P&gt;&lt;P&gt;You can check all these phases on the ASA using the Packet Tracer command:-&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2015 06:22:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700067#M190948</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-05T06:22:33Z</dc:date>
    </item>
    <item>
      <title>Thx Vibhor, however, I wonder</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700068#M190949</link>
      <description>&lt;P&gt;Thx Vibhor, however, I wonder why when I traceroute, the first hop is to outside interface but didn't following the route. So I want to confirm whether to add the NAT exemption station can solve my problem.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2015 06:43:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700068#M190949</guid>
      <dc:creator>Kurt Lei</dc:creator>
      <dc:date>2015-06-05T06:43:24Z</dc:date>
    </item>
    <item>
      <title>Hi,No , NAT exemption wouldn</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700069#M190950</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;No , NAT exemption wouldn't help with that.&lt;/P&gt;&lt;P&gt;You can check this document about the trace route and how it works on ASA device:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html#trace&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2015 08:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700069#M190950</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-05T08:17:40Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor,Thanks for your</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700070#M190951</link>
      <description>&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;Thanks for your advise. Actually, I'm still struggling on this case. In fact, there is a Solarwind server is responsible to collect the syslog of ASA. I found ASA is failed to&amp;nbsp;The solarwind is placed at inside zone, when I traceroute from ASA to Solarwind and found the traffic is going to Outside zone. I am wonder why the traffic is still going to outside even there is a static route to inside zone.&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.0.0.0 10.131.3.1 &amp;lt;---- Inside zone&lt;/P&gt;&lt;P&gt;Can you give me some suggestion ?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 06:52:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700070#M190951</guid>
      <dc:creator>Kurt Lei</dc:creator>
      <dc:date>2015-06-08T06:52:54Z</dc:date>
    </item>
    <item>
      <title>Hi,Firstly , Check for</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700071#M190952</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Firstly , Check for existing connections for this Server IP , If it is pointing to the Outside interface , it would override the route statement.&lt;/P&gt;&lt;P&gt;Secondly , Try to check the policy flow using the Packet Tracer:-&lt;/P&gt;&lt;P&gt;https://supportforums.cisco.com/document/29601/troubleshooting-access-problems-using-packet-tracer&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2015 14:18:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700071#M190952</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-06-08T14:18:21Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor,I found no any</title>
      <link>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700072#M190953</link>
      <description>&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;I found no any connection entry of the server in ASA.&lt;/P&gt;&lt;P&gt;And&amp;nbsp;I finally got the show route from the customer. It's really strange, there is no static route on the configuration but there is an entry when show route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S &amp;nbsp; &amp;nbsp;10.130.0.0 255.255.0.0 [1/0] via (Outside GW), outside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, I have another issue is that some subnet should go to this Outside gateway. The criteria is that only the inside subnet (i.e. 10.131.3.0) will back to MPLS connection and should use below route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;S &amp;nbsp; &amp;nbsp;10.0.0.0 255.0.0.0 [1/0] via 10.131.3.1, inside&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know there is no any policy routing in ASA 8.0, how can I achieve it ?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 02:21:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-8-0-nat0-statement-problem/m-p/2700072#M190953</guid>
      <dc:creator>Kurt Lei</dc:creator>
      <dc:date>2015-06-09T02:21:28Z</dc:date>
    </item>
  </channel>
</rss>

