<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Startup config error after upgrading to ASA from PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/startup-config-error-after-upgrading-to-asa-from-pix/m-p/2203537#M356782</link>
    <description>&lt;P&gt;Hey guys.&amp;nbsp; I get the following startup-config errors when reloading our ASA.&amp;nbsp; A pix-&amp;gt;asa conversion was just done on it.&amp;nbsp; The ASA is currently running 8.2(5), and I am trying to get ready to update it to the most stable release, and wanted to make sure all my ducks are in a row.&amp;nbsp; What is going on with the "will be identity translated for outbound"? This is part of the VPN configuration, and I understand nat0 is saying to not nat it.&amp;nbsp; Is this something that I should be worried about?&amp;nbsp; The ASA is not in production currently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need further information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.........nat 0 10.37.0.116 will be identity translated for outbound&lt;/P&gt;&lt;P&gt;*** Output from config line 406, "nat (inside) 0 10.37.0.1..."&lt;/P&gt;&lt;P&gt;nat 0 xx.xx.xx.xx (PUBLIC IP) will be identity translated for outbound&lt;/P&gt;&lt;P&gt;*** Output from config line 431, "nat (inside) 0 xx.xx.xx..."&lt;/P&gt;&lt;P&gt;.........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Line 406&lt;/P&gt;&lt;P&gt;nat (inside) 0 10.37.0.116 255.255.255.255&lt;/P&gt;&lt;P&gt;Line 431&lt;/P&gt;&lt;P&gt;nat (inside) 0 xx.xx.xx.xx (PUBLIC IP) 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Corresponding global&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_inbound_nat0_acl outside&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL&lt;/P&gt;&lt;P&gt;access-list outside_inbound_nat0_acl extended permit ip 172.16.16.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl extended permit ip any 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl extended permit ip 10.37.0.0 255.255.0.0 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl extended permit ip 172.31.0.0 255.255.0.0 172.16.16.0 255.255.255.0&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:59:22 GMT</pubDate>
    <dc:creator>mark.kimzey</dc:creator>
    <dc:date>2019-03-12T00:59:22Z</dc:date>
    <item>
      <title>Startup config error after upgrading to ASA from PIX</title>
      <link>https://community.cisco.com/t5/network-security/startup-config-error-after-upgrading-to-asa-from-pix/m-p/2203537#M356782</link>
      <description>&lt;P&gt;Hey guys.&amp;nbsp; I get the following startup-config errors when reloading our ASA.&amp;nbsp; A pix-&amp;gt;asa conversion was just done on it.&amp;nbsp; The ASA is currently running 8.2(5), and I am trying to get ready to update it to the most stable release, and wanted to make sure all my ducks are in a row.&amp;nbsp; What is going on with the "will be identity translated for outbound"? This is part of the VPN configuration, and I understand nat0 is saying to not nat it.&amp;nbsp; Is this something that I should be worried about?&amp;nbsp; The ASA is not in production currently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need further information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.........nat 0 10.37.0.116 will be identity translated for outbound&lt;/P&gt;&lt;P&gt;*** Output from config line 406, "nat (inside) 0 10.37.0.1..."&lt;/P&gt;&lt;P&gt;nat 0 xx.xx.xx.xx (PUBLIC IP) will be identity translated for outbound&lt;/P&gt;&lt;P&gt;*** Output from config line 431, "nat (inside) 0 xx.xx.xx..."&lt;/P&gt;&lt;P&gt;.........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Line 406&lt;/P&gt;&lt;P&gt;nat (inside) 0 10.37.0.116 255.255.255.255&lt;/P&gt;&lt;P&gt;Line 431&lt;/P&gt;&lt;P&gt;nat (inside) 0 xx.xx.xx.xx (PUBLIC IP) 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Corresponding global&lt;/P&gt;&lt;P&gt;nat (outside) 0 access-list outside_inbound_nat0_acl outside&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_outbound_nat0_acl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACL&lt;/P&gt;&lt;P&gt;access-list outside_inbound_nat0_acl extended permit ip 172.16.16.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl extended permit ip any 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl extended permit ip 10.37.0.0 255.255.0.0 172.16.16.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list inside_outbound_nat0_acl extended permit ip 172.31.0.0 255.255.0.0 172.16.16.0 255.255.255.0&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:59:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/startup-config-error-after-upgrading-to-asa-from-pix/m-p/2203537#M356782</guid>
      <dc:creator>mark.kimzey</dc:creator>
      <dc:date>2019-03-12T00:59:22Z</dc:date>
    </item>
    <item>
      <title>Startup config error after upgrading to ASA from PIX</title>
      <link>https://community.cisco.com/t5/network-security/startup-config-error-after-upgrading-to-asa-from-pix/m-p/2203538#M356783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that there is no problem as the firewall has not given any kind of error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do personally wonder sometimes why is it so (atleast in the 8.2 softares etc) that the firewall shows a message on the CLI when you are for example configuring a "global" / "nat" command pair.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if this falls into the same category.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration format for NAT has stayed pretty same leading to the 8.2 softwares. I'm not totally sure what software you are going to go for but you seem to have the latest 8.2 series software so next steps are already 8.3 / 8.4 / 9.0 / 9.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ALL of the above mentioned softwares introduce a completely new NAT configuration format to the ASA. While the ASA automatically converts the configurations its not always 100% process not to mention that the NAT configuration probably is far from optimal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Feb 2013 07:21:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/startup-config-error-after-upgrading-to-asa-from-pix/m-p/2203538#M356783</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-02-12T07:21:02Z</dc:date>
    </item>
    <item>
      <title>Startup config error after upgrading to ASA from PIX</title>
      <link>https://community.cisco.com/t5/network-security/startup-config-error-after-upgrading-to-asa-from-pix/m-p/2203539#M356784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the confirmation.&amp;nbsp; I got her to 8.45 for now and plan on deploying it this weekend.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 05:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/startup-config-error-after-upgrading-to-asa-from-pix/m-p/2203539#M356784</guid>
      <dc:creator>mark.kimzey</dc:creator>
      <dc:date>2013-02-13T05:23:43Z</dc:date>
    </item>
  </channel>
</rss>

