cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
591
Views
0
Helpful
3
Replies

Are we using NAT

1salvarez
Level 1
Level 1

We have a VPN conenction with a business partner. I need to know if our ASA is NATin'g the traffic to their router.

Thanks.

1 Accepted Solution

Accepted Solutions

Hello,

The ASA is not making translation just on the traffic related to ACL inside_nat0_outbound, So VPN traffic should be in that ACL.

Please rate helpful posts

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

View solution in original post

3 Replies 3

Julio Carvajal
VIP Alumni
VIP Alumni

Hello,

Please provide us the show run nat:

If you see a nat like this nat ( inside) 0 access-list xxxxx

Please provide the show run access-list xxxx

Regards,

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

Changed the first octet.

nat (inside) 0 access-list inside_nat0_outbound

nat (inside) 99 111.16.1.0 255.255.255.0

nat (inside) 99 112.16.2.0 255.255.255.0

nat (inside) 99 113.168.1.0 255.255.255.0

nat (inside) 99 114.168.2.0 255.255.255.0

nat (inside) 99 115.168.6.0 255.255.255.0

nat (inside) 99 116.168.7.0 255.255.255.0

nat (inside) 99 117.168.8.0 255.255.255.0

nat (inside) 99 118.168.20.0 255.255.255.0

nat (inside) 99 119.168.21.0 255.255.255.0

nat (inside) 99 120.168.22.0 255.255.255.0

nat (inside) 99 121.168.23.0 255.255.255.0

nat (inside) 99 122.168.24.0 255.255.255.0

nat (inside) 99 123.168.25.0 255.255.255.0

nat (inside) 99 124.168.4.0 255.255.254.0

nat (inside) 99 125.20.0.0 255.255.0.0

nat (inside) 1 0.0.0.0 0.0.0.0

Hello,

The ASA is not making translation just on the traffic related to ACL inside_nat0_outbound, So VPN traffic should be in that ACL.

Please rate helpful posts

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card