cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1706
Views
0
Helpful
5
Replies

8.3 order of nat

sonybabu2k1
Level 1
Level 1

Hi,

I have a doubt regarding order of nat in 8.3. In cisco documentation at one place it says that order is


–Network object NAT—Automatically ordered in the NAT table.

–Twice NAT—Manually ordered in the NAT table (before or after network object NAT rules).

http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118634

But in another place in table the order is like:

Section 1 - Twice NAT

Section 2 - Network object NAT

Section 3 - Twice NAT configured in section 3

http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118157

Could anyone please clarify on this ?

Thank you

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

Hi Sony,

Yes, the documentation is correct.

The NAT order of operation is:

Section 1 - Twice NAT

Section 2 - Network object NAT

Section 3 - Twice NAT configured in section 3

However, within Section 2 itself - Network object NAT - the operation is automatically ordered in the NAT table.

Hope that makes sense.

View solution in original post

5 Replies 5

Jennifer Halim
Cisco Employee
Cisco Employee

Hi Sony,

Yes, the documentation is correct.

The NAT order of operation is:

Section 1 - Twice NAT

Section 2 - Network object NAT

Section 3 - Twice NAT configured in section 3

However, within Section 2 itself - Network object NAT - the operation is automatically ordered in the NAT table.

Hope that makes sense.

Hi halijenn,

Thanks for the reply, so the first one (shown below) is incorrect. right ?

–Network object NAT—Automatically ordered in the NAT table.
–Twice NAT—Manually ordered in the NAT table (before or after network object NAT rules).
http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118634

Thanks

Sony

Yes, you are absolutely right. The Twice NAT section 1 should come first before Network object NAT, as per the following:

http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1118157

I think what the document means to say is (for that particular section of Order of NAT rules) is to use "Network object NAT" first whenever possible, and only use "Twice NAT" if you can't configure it via "Network object NAT".

Thanks halijenn, i think the documentation is a bit confusing. I would appreciate if you could inform documentation people about this.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card