<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FWSM NAT-Control in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516768#M623937</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;pkampana wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do "sh run all | i nat-control" to check if it is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without nat-control enabled all hosts that do NOT match an existing nat or static will be translated to themselves. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Hello Pkampana,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explore more please ur last line still not clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One PC in&amp;nbsp; PAK_IT wants to access MAC_IT,access-list was OK any any&amp;nbsp; on PAK_IT interface but still i was not able to access but when i put&amp;nbsp; the static command it worked, Customer told me that NAT control is&amp;nbsp; disable,I use the ASA command sh Nat-control&amp;nbsp; and it gave me error ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explain me the below static command ???? If i m not wrong&amp;nbsp; The user with 172.25.51.26 want to reach any PC (According to ACL) in 172.25.52.0 he will access by IP 172.25.52.26, Correct me if i m wrong ?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan51&lt;BR /&gt; nameif PAK_IT&lt;BR /&gt; security-level 25&lt;BR /&gt; ip address 172.25.51.254 255.255.255.0 standby 172.25.51.253&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan52&lt;BR /&gt; nameif MAC_IT&lt;BR /&gt; security-level 90&lt;BR /&gt; ip address 172.25.52.254 255.255.255.0 standby 172.25.52.253&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (PAK_IT,MAC_IT) 172.25.52.26 172.25.51.26 netmask 255.255.255.255&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 05 Oct 2010 17:21:53 GMT</pubDate>
    <dc:creator>estelamathew</dc:creator>
    <dc:date>2010-10-05T17:21:53Z</dc:date>
    <item>
      <title>FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516766#M623934</link>
      <description>&lt;P&gt;Hello Friends,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we disable Nat-control in FWSM, And if we disable Nat and if suppose i want to use static Nat command then is it will be effected in the configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is command in FWSM to see NAT is enable or disable,as i know in ASA it sh Nat-control command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516766#M623934</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2019-03-11T18:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516767#M623936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can do "sh run all | i nat-control" to check if it is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without nat-control enabled all hosts that do NOT match an existing nat or static will be translated to themselves. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 15:23:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516767#M623936</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-05T15:23:59Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516768#M623937</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;pkampana wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do "sh run all | i nat-control" to check if it is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without nat-control enabled all hosts that do NOT match an existing nat or static will be translated to themselves. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Hello Pkampana,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explore more please ur last line still not clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One PC in&amp;nbsp; PAK_IT wants to access MAC_IT,access-list was OK any any&amp;nbsp; on PAK_IT interface but still i was not able to access but when i put&amp;nbsp; the static command it worked, Customer told me that NAT control is&amp;nbsp; disable,I use the ASA command sh Nat-control&amp;nbsp; and it gave me error ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can u explain me the below static command ???? If i m not wrong&amp;nbsp; The user with 172.25.51.26 want to reach any PC (According to ACL) in 172.25.52.0 he will access by IP 172.25.52.26, Correct me if i m wrong ?????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan51&lt;BR /&gt; nameif PAK_IT&lt;BR /&gt; security-level 25&lt;BR /&gt; ip address 172.25.51.254 255.255.255.0 standby 172.25.51.253&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan52&lt;BR /&gt; nameif MAC_IT&lt;BR /&gt; security-level 90&lt;BR /&gt; ip address 172.25.52.254 255.255.255.0 standby 172.25.52.253&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (PAK_IT,MAC_IT) 172.25.52.26 172.25.51.26 netmask 255.255.255.255&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 17:21:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516768#M623937</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-10-05T17:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516769#M623938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This static translates host 172.25.52.26 behind interface&amp;nbsp; PAK_IT ot itself for interface MAC_IT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need a static even if you have nat control disabled if you had any existing nats or statics that were matching 172.25.52.26 behind the PAK_IT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if you hada &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (PAK_IT) 1 172.25.52.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you would need a static to make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 17:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516769#M623938</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-05T17:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516770#M623939</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;pkampana wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This static translates host 172.25.52.26 behind interface&amp;nbsp; PAK_IT ot itself for interface MAC_IT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will need a static even if you have nat control disabled if you had any existing nats or statics that were matching 172.25.52.26 behind the PAK_IT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example if you hada &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (PAK_IT) 1 172.25.52.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then you would need a static to make it work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;Hello Pkampana,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 2&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 3&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(inside,outside) 202.1.1.1 10.10.10.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above static command says host on inside (10.10.10.1) when it goes on internet it translates to 202.1.1.1&lt;/P&gt;&lt;P&gt;and also when users from outside want to access host on inside they will hit to 202.1.1.1 which will be translate to 10.10.10.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As u have mentioned below&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;This static translates host 172.25.52.26 behind interface&amp;nbsp; PAK_IT ot itself for interface MAC_IT.&lt;/PRE&gt;&lt;P&gt;there is no such 172.25.52.26 host this is a virtual IP the real IP is 172.25.51.26. so what i understand is when 172.25.51.26 want to access MAC_IT it will be translate to 172.25.52.26. This is what u mean to say??????????????? please correct me if i m wrong.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example: the user is coming from lower security level to inside higher security level so the statement will be&amp;nbsp; (outside,inside).so in this case PAK_IT is outside and MAC_IT is inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;You will need a static even if you have nat control disabled if you had any existing nats or statics that were matching 172.25.52.26 behind the PAK_IT.&lt;/PRE&gt;&lt;P&gt;There were no static or Nat statement for this IP But there were other static statement between PAK_IT and MAC_IT for other Ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Oct 2010 19:11:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516770#M623939</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-10-05T19:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516771#M623940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dear's&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anybody helpme on the above query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 13:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516771#M623940</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-10-06T13:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516772#M623941</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you notice what syslog was being produced before putting in the particular static between PAC_IT and MAC_IT? This should give us a better idea of what was wrong with NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, what does the output of "show run all | in nat-control" give you like pkampana had asked before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 14:58:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516772#M623941</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-10-06T14:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516773#M623942</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dear's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 PC in 172.25.51.26 in PAK_IT want to access a subnet in 172.25.52.0 MAC_IT,The static statement is working fine and PC 172.25.51.26 is accessing MAC-IT whole subnet.&amp;nbsp; Just want to explore more what this static statement means???&amp;nbsp; As i have mentioned in above mail is correct for the static statment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, what does the output of "show run all | in nat-control" give you&amp;nbsp; like pkampana had asked before?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen by the command and Nat-control is disable,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 20:22:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516773#M623942</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-10-06T20:22:23Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM NAT-Control</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516774#M623943</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Estela,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will attempt to answer your questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (PAK_IT,MAC_IT) 172.25.52.26 172.25.51.26 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You asked:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;there is no such 172.25.52.26 host this is a virtual IP the real IP is&amp;nbsp; 172.25.51.26. so what i understand is when 172.25.51.26 want to access&amp;nbsp; MAC_IT it will be translate to 172.25.52.26. This is what u mean to&amp;nbsp; say??????????????? please correct me if i m wrong.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static command translates host 172.25.51.26 to IP 172.25.52.26 when traffic traverses from the PAK_IT to the MAC_IT interface.&amp;nbsp; Therefore, when host 172.25.51.26 needs to access resources behind the MAC_IT interface, the traffic will appear to have originated from IP address 172.25.52.26 to the hosts behind the MAC_IT interface.&amp;nbsp; Likewise, if hosts behind the MAC_IT interface need to access resources on host 172.25.51.26, they will need to access it using the translated address (172.25.52.26) and not the real IP.&amp;nbsp; The static NAT works in both directions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The logic is similar to the example you provided:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface vlan 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nameif inside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;security-level 100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface vlan 3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;nameif outside&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;security-level 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static(inside,outside) 202.1.1.1 10.10.10.1 netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The above static command says host on inside (10.10.10.1) when it goes on internet it translates to 202.1.1.1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;and also when users from outside want to access host on inside they will hit to 202.1.1.1 which will be translate to 10.10.10.1. &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The command "nat-control" determines whether NAT is required when traffic traverses the FWSM.&amp;nbsp; If nat-control is enabled, you will see the following when you execute the command "show run all | inc nat-control":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM/admin# show run all nat-c&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Likewise, if nat-control is disabled, you will see the following:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;FWSM/admin(config)# show run all nat-c&lt;/DIV&gt;&lt;DIV&gt;no nat-control&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;However, even if you have nat-control disabled, if there is a NAT statement associated with an interface, a translation will still be required when traffic traverses that interface.&amp;nbsp; For example:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;no nat-control&lt;/DIV&gt;&lt;DIV&gt;static (PAK_IT,MAC_IT) 172.25.52.26 172.25.51.26 netmask 255.255.255.255&lt;/DIV&gt;&lt;DIV&gt;global (MAC_IT) 1 interface&lt;/DIV&gt;&lt;DIV&gt;nat (PAK_IT) 1 0 0&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;With the above NAT and STATIC statements, host 172.25.51.26 is translated to 172.25.52.26, and all other hosts behind the PAK_IT interface will be PAT'ed to the MAC_IT interface IP.&amp;nbsp; So in this case, even though nat-control is disabled, a translation is still required because the command "nat (PAK_IT) 1 0 0" is enforcing NAT for all hosts behind the PAK_IT interface.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Likewise, if you had the following example:&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;no nat-control&lt;/DIV&gt;&lt;DIV&gt;static (PAK_IT,MAC_IT) 172.25.52.26 172.25.51.26 netmask 255.255.255.255&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Then only host 172.25.51.26 will be translated due to the static statement.&amp;nbsp; No other hosts will require a translation.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;To determine whether a translation is required, you can look at the output of "show run nat" and show run global", this will tell you if any NAT statements are configured.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Hope this helps.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Oct 2010 22:10:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-nat-control/m-p/1516774#M623943</guid>
      <dc:creator>Allen P Chen</dc:creator>
      <dc:date>2010-10-06T22:10:31Z</dc:date>
    </item>
  </channel>
</rss>

