cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
275
Views
0
Helpful
2
Replies

ASA 8.2 code and static nat's

cperkins22
Level 4
Level 4

So quick and easy question "I hope".

i have a asa configured on an internal network and I see that there's a static statement for each interface combination but it's just saying nat the ip to itself which seems to be pointless.

Are these statements even needed?  I know you always need "NAT, route, rule" but this seems ridiculous.

static (inside,outside) 0.0.0.0 0.0.0.0 netmask 255.255.255.255
static (inside,warehouse) 0.0.0.0 0.0.0.0 netmask 255.255.255.255
static (warehouse,inside) 0.0.0.0 0.0.0.0 netmask 255.255.255.255
static (nowhere,inside) 0.0.0.0 0.0.0.0 netmask 255.255.255.255

2 Replies 2

teatrodelsogno
Level 1
Level 1

Hi,
seems strange configuration?

did you inherit this configuration from another security engineer?

Yes it's strange.  I did inherit it.  A "sh nat" shows no translate_hits for any of them so I think it's safe to remove it but I have hundreds of asa's with this statement so before removing it I want to make certain I understand why it's doing.

I'm trying to get the config ready to upgrade to 8.4 therefore I want to eliminate any erroneous code.

Review Cisco Networking products for a $25 gift card