cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2013
Views
0
Helpful
1
Replies

ASA nat access list hit count

edd.phillips
Level 1
Level 1

Can someone tell me why v7.2 of the PIX/ASA OS doesn't register hits on an access list used for nat? I always used this on v6 to check the rule was working. The show nat command seems to be a bit random with it's counters as well. Is there another way to monitor the nat rules that i'm missing?

1 Reply 1

Farrukh Haroon
VIP Alumni
VIP Alumni

I think to speed up things, for existing sessions (already in the state table) NAT policy and various other lookups etc are not performed. Perhaps this is the reason why you are seeing this behavior. So you will see a hit in the NAT statement for only the first packet in the flow (or based on some other similar criteria).

Regards

Farrukh

Review Cisco Networking for a $25 gift card