11-21-2016 08:04 AM - edited 03-12-2019 06:10 PM
So quick and easy question "I hope".
i have a asa configured on an internal network and I see that there's a static statement for each interface combination but it's just saying nat the ip to itself which seems to be pointless.
Are these statements even needed? I know you always need "NAT, route, rule" but this seems ridiculous.
static (inside,outside) 0.0.0.0 0.0.0.0 netmask 255.255.255.255
static (inside,warehouse) 0.0.0.0 0.0.0.0 netmask 255.255.255.255
static (warehouse,inside) 0.0.0.0 0.0.0.0 netmask 255.255.255.255
static (nowhere,inside) 0.0.0.0 0.0.0.0 netmask 255.255.255.255
11-21-2016 08:50 AM
Hi,
seems strange configuration?
did you inherit this configuration from another security engineer?
11-21-2016 12:20 PM
Yes it's strange. I did inherit it. A "sh nat" shows no translate_hits for any of them so I think it's safe to remove it but I have hundreds of asa's with this statement so before removing it I want to make certain I understand why it's doing.
I'm trying to get the config ready to upgrade to 8.4 therefore I want to eliminate any erroneous code.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide