cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2680
Views
0
Helpful
32
Replies

ASA Outside NAT Problem!!!

andyc0313
Level 1
Level 1

Hi everybody,

My situation is as follows:
My Pre 8.3 ASA is connected to two outside networks: the ISP with security level 0, and a separate agency network with security level 10.  We are having a problem connecting to the agency network from a L2L VPN tunnel coming through the ISP interface.  These VPN branch users can communicate with our entire corporate network and I'm currently using outside-to-outside nat to get them to talk to the internet out the same ISP interface they come in through, but they can't talk to the agency network at all. *All inside users have full communication with the agency network.*  

I receive the following error:
------------------------------
asa1# sh nat outside agency
ERROR: No matching NAT policy found
------------------------------
If I statically nat one user from the VPN branch to one of the agency pool addresses, I have full connectivity between that VPN user and the agency network.
This command makes it work: static (outside,agency) 16x.5x.1x.12x 10.18.1.1

My configuration:
nat (outside) 20 access-list vpn_outside_nat
nat (inside) 0 access-list NONAT
nat (inside) 30 access-list inside_nat_outbound
nat (inside) 20 0.0.0.0 0.0.0.0
global (agency) 20 16x.5x.1x.1x-1x.5x.1x.12x
global (agency) 20 16x.5x.1x.1x
global (outside) 20 20x.1x.2x.1x
global (outside) 10 20x.1x.2x.1x netmask 255.255.255.0
global (outside) 30 20x.1x.2x.1x netmask 255.255.255.255

access-list vpn_outside_nat extended permit ip 10.0.0.0 255.0.0.0 any

access-list NONAT extended permit ip any 10.0.0.0 255.0.0.0

access-list inside_nat_outbound extended permit ip host 192.168.1.12 any

 


Please let me know if you need any more information to help.  I appreciate any answers!  
Thanks!

32 Replies 32

I do not think there is anything missing in the configuration...I have been meaning to lab this but I don't have access to any ASAs running 8.2.

Would you be able to open a TAC case to see what Cisco has to say about this?

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts

It looks like I need a current service contract to open a case with Cisco, is this correct?  I don't have any service contracts with them at the moment.

Yes you would need a current service contract to open a case directly with TAC.  Otherwise you will need to go through a Cisco partner.

--

Please remember to select a correct answer and rate helpful posts

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card