07-16-2018 06:29 PM - edited 02-21-2020 07:59 AM
Hi Everyone
1. nat (inside,any) source static INSIDE INSIDE destination static SITE1 SITE1
2. nat (inside,twbc) source static INSIDE INSIDE destination static SITE2 SITE2
3. nat (inside,twbc) source static INSIDE INSIDE destination static SITE3 SITE3
4. nat (inside twbc) source static INSIDE INSIDE destination static SITE4 SITE4
5. nat (inside,mpls) source static INSIDE INSIDE destination static SITE4 SITE4
[...]
Referring to above entries.
Assuming ASA already hit entry 4, will it still process to read entry 5?.. and the rest of the nat entries?
Or will stop at entry 4 and doesn't read the rest of the entries
We're running asa991-smp-k8
Thanks,
Jon
07-16-2018 08:05 PM
Not sure what your requirement is but, looking at your ingress and egress interfaces on statements 4 and 5 they are different, yet source and destination IP are the same. If you want different NAT based on ingress and egress interface, you could also consider object NAT, but this gets treated at the bottom.
07-16-2018 11:02 PM
The answer to your question is that the processing of the NAT rules stop after finding a hit. But the answer to your problem is the keyword „route-lookup“ at the end of the NAT statement.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide