cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


298
Views
0
Helpful
8
Replies
Beginner

NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Hello

 

Can someone enlighten me when to append no-proxy-arp route-lookup for the identity manual NAT/NAT Exempt for 9.9? Or is there a best practice for this?

Everyone's tags (1)
8 REPLIES 8
Highlighted
VIP Advisor

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Migrating from 8.2 to 9.9 is not an straight forward, you need to look upgrade path. ( i suggest to stick your latest OS with 5 Start rating, until you have rason to go 9.9)

 

there is lot of changes from 8.2 to 8.4, so i suggest to understand the chages and make the upgrade plan accordingly.

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa83/upgrading/migrating.html

 

BB
*** Rate All Helpful Responses ***
Beginner

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Hi

 

Yes, actually i'm converting the pre8.3 to post8.4 nat configs line by line manually. I'm just confuse when to append the no-proxy-arp route-lookup for the post8.4 nat exempt

Enthusiast

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Hi,

For upgrading ASA from 8.2 to 9.9, you need to upgrade to 8.4 first. 

Upgrade Path

8.2(x) → 8.4(6) →9.9(x)

Please go through the release note before upgrade, there are lot of changes from 8.2 to 9.9. For identity nat ASA not required to answer the arp quires.

 

HTH

Abheesh

 

Beginner

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Hi @Abheesh Kumar

 

Actually i will not do an upgrade, i will replace the 8.2 firewall with a 9.9 firewall that is why i am migrating the configuration manually. So for 9.9 NAT Exempt configuration, i need to append no-proxy-arp route-lookup?

Enthusiast

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Hi,
For identity nat ASA does not act as a Proxy Server of the subnet used in the NAT statement. It should lookup the route and reach the destination. So for identity nat required no-proxy-arp route-lookup

HTH
Abheesh
Beginner

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Hi

What will be the impact if i don't append no-proxy-arp route-lookup? will it not reach the destination?
Enthusiast

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

Hi,

Below doc can help you to understand more about proxy-arp, route-lookup are where to be used.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/nat_objects.html

 

HTH

Abheesh

Rising star

Re: NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

might this link could help/make your life bit easier to you convert the pre 8.3 to post 8.4 nat

 

 https://www.tunnelsup.com/nat-converter/

please do not forget to rate.