03-26-2018 07:55 AM
Hello!!!
I want to change nat policy order via CLI.
I want rule number 3 move to number 2 and rule number 4 move to number 3.
ASA5510 version 8.0
ASA(config)# show nat inside srb
match ip inside 192.168.1.0 255.255.255.0 srb 192.168.100.0 255.255.255.0
NAT exempt
translate_hits = 0, untranslate_hits = 0
match ip inside 192.168.1.0 255.255.255.0 srb any
static translation to 192.168.1.0
translate_hits = 1754, untranslate_hits = 19490
match ip inside 192.168.1.0 255.255.255.0 srb 192.168.10.0 255.255.255.0
dynamic translation to pool 10 (172.16.101.0)
translate_hits = 0, untranslate_hits = 0
match ip inside 192.168.1.0 255.255.255.0 srb 172.16.201.0 255.255.255.0
dynamic translation to pool 10 (172.16.101.0)
translate_hits = 0, untranslate_hits = 0
match ip inside 172.16.101.0 255.255.255.0 srb any
dynamic translation to pool 20 (No matching global)
translate_hits = 0, untranslate_hits = 0
match ip inside 192.168.1.0 255.255.255.0 srb any
dynamic translation to pool 20 (No matching global)
translate_hits = 0, untranslate_hits = 0
match ip inside any srb any
no translation group, implicit deny
policy_hits = 0
Solved! Go to Solution.
03-26-2018 04:01 PM
Please ask this question under firewall section of community site. I am unable to move this question to that space.
THis is policy and Access where you can ask questions about ISE, Trustsec, Anyconnect, ACS etc.
-Krishnan
03-26-2018 04:01 PM
Please ask this question under firewall section of community site. I am unable to move this question to that space.
THis is policy and Access where you can ask questions about ISE, Trustsec, Anyconnect, ACS etc.
-Krishnan
03-26-2018 07:52 PM
This might help:
ASA Network Address Translation Configuration Troubleshooting - Cisco
says,
...
Solution:
NAT rules can be reordered with the CLI if you remove the rule and reinsert it at a specific line number. In order to insert a new rule at a specific line, enter the line number just after the interfaces are specified.
Example:
ASA(config)# nat (inside,outside) 1 source static 10.10.10.0-net
10.10.10.0-net destination static 192.168.1.0-net 192.168.1.0-net
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide