Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Firewalls Community


problem with no nat after upgrade version

Hello Guys...

Im having problems with nat after upgrade....

source =

destination =

the next hop for 10.0.32/24 is, by inside interface. My firewall Pings this When I change the router to doesnt pass by firewall, the connection works from source to destination, works!

In log, im receiving this message:

6Nov 23 201215:24:54302303spbwts02_03035551710.0.32.1080Built TCP state-bypass connection 249015 from dmz:spbwts02_0303/55517 (spbwts02_0303/55517) to inside: ( /80)

6Nov 23 201215:27:29302304spbwts02_03035112310.0.32.1080Teardown TCP state-bypass connection 242785 from dmz:spbwts02_0303/51123 to inside: duration 1:00:10 bytes 0 Connection timeout

In 8.2 I had this NAT:

DMZ interface:

Exempt     (outbound)

I have a bypass for those networks and services. I guess I dont need bypass because the packet comes from dmz and goes to inside, right? Anyway, I removed bypass and nothing happen!

And now, in 8.4(5) I have:

DMZ     Inside     obj-     obj-     any      original     original    

What can be my problem?


problem with no nat after upgrade version

You may have encountered the change of NAT behavior from 8.4(2). Check the "Lookup route table to locate egress interface" checkbox in your identity NAT rule. (This is the route-lookup option in CLI.)

Paste your config if that does not help.

problem with no nat after upgrade version

Hi Peter!

I changed the route for that network and worked!

But I needed to keep the bypass. I didnt understand why, because the traffic comes from DMZ and goes to INSIDE.


problem with no nat after upgrade version

Fine, but what did you change exactly?

problem with no nat after upgrade version

route, look:


route inside 1

Now and working:

route inside 1

I dont have an interface in the network. I guess when someone configured the route, put this as gateway, but I dont know how it was working.

Now, I changed to and OK. My firewall has an interface in newtork.

But the bypass is a mistery to me yet!