Is this possible - ASA5512-X
Outside Address /27 Public - Inside Address Private /24
I have basic NAT configured but would like to apply a public IP to an "inside" address with no-NAT. Now I have managed this before by splitting the /27 and creating a /28 routed VLAN network using half the public IPs - but it wastes addresses.
On the old 8.x software you could configure allow addresses to pass without translation. Is this possible now?
Not exactly sure what your question is but it appears to me you are looking for NoNAT configuration for post 8.2 version of Cisco ASA, if so then here's what you need :
Let's say :
internal subnet : 10.10.10.0/24
External Subnet : 188.8.131.52/24
now you want 10.10.10.0/24 to go to 184.108.40.206/24 untranslated and avoid the dynamic Pat :
object network OBJ-10.10.10.0
subnet 10.10.10.0 255.255.255.0
object network OBJ-220.127.116.11
subnet 18.104.22.168 255.255.255.0
nat (inside,outside) source static OBJ-10.10.10.0 OBJ-10.10.10.0 destination static OBJ-22.214.171.124 OBJ-126.96.36.199
Hope I understood your request correctly.
I believe I ran into your issue last night. If that happens again double check your service-policy thru CLI
1. Class map "match address"
2. policy-map - apply your class and any other parameters
3. policy-map should be in your service-policy...
If service-policy is gone then you are not inspecting anything and therefore all traffic that is being logged is your NAT traffic... I lost SNMP and Netflow which was a flag of this issue.