cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1015
Views
0
Helpful
3
Replies

ASA NAT question

meidanmeshulam
Level 1
Level 1

Hi everyone,

Here's my question, given the next NAT rule:
nat (any,DMZ) source static any any destination static nat_12.164.193.111 vip_172.24.56.77 unidirectional description abcd ,
Does the Cisco ASA uses the outgoing interface as a matching criteria for that NAT rule ?
If so, how can the ASA know, what is the exit interface ??? Nat is prior to Egress interface as far as I know.

Thanks a lot !


3 Replies 3

Francesco Molino
VIP Alumni
VIP Alumni

Hi

In terms of order of operations, traffic from inside to outside (from your other zones to this dmz zone), routing comes right before nat and this how it knows where the next hop is.


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Thanks for your replay,

So in my case the traffic is actually coming from the outside (Internet int) to the DMZ and not vice versa.
regardless, are you sure that routing comes before NAT ? can you back it up ?

 

Thank you !

I’m re-reading my post and I replied wrong for ASA. My reply stands for routers for inside to outside. 

On ASA, however, nat comes before l3 route module; it uses the interface you configure. 

 

 


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
Review Cisco Networking for a $25 gift card