03-31-2021 10:30 AM
Hi everyone,
Here's my question, given the next NAT rule:
nat (any,DMZ) source static any any destination static nat_12.164.193.111 vip_172.24.56.77 unidirectional description abcd ,
Does the Cisco ASA uses the outgoing interface as a matching criteria for that NAT rule ?
If so, how can the ASA know, what is the exit interface ??? Nat is prior to Egress interface as far as I know.
Thanks a lot !
03-31-2021 09:01 PM
Hi
In terms of order of operations, traffic from inside to outside (from your other zones to this dmz zone), routing comes right before nat and this how it knows where the next hop is.
04-01-2021 06:52 AM
Thanks for your replay,
So in my case the traffic is actually coming from the outside (Internet int) to the DMZ and not vice versa.
regardless, are you sure that routing comes before NAT ? can you back it up ?
Thank you !
04-02-2021 07:16 PM
I’m re-reading my post and I replied wrong for ASA. My reply stands for routers for inside to outside.
On ASA, however, nat comes before l3 route module; it uses the interface you configure.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide