cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
459
Views
0
Helpful
2
Replies

Identity NAT on ASA running Version 9.0(1)

Bouki
Level 1
Level 1

Hi guys,

 

I cannot have access without Identity NAT configured.

 

Object: LAN

 

object network LAN
 subnet 10.100.52.0 255.255.255.0

 

NAT:

object network LAN
 nat (inside,outside) static 10.100.52.0 no-proxy-arp route-lookup

 

I want to emphasise that there is not PAT configured and this is the only NAT statement configured on the box , without it I cannot access the Internet.

 

Why do I need the Identity NAT if there is no other statement shadowing it?

 

Many thanks

 

2 Replies 2

Does you upstream router has a route-back towards your natted IP or do you
have an ACL rule limiting internet access on other IPs.

Yes, there are routes defined statically back to those natted IP addresses