Commands to clear dynamic items when making config changes on ASA
Please forgive me if this is not a good section to ask this question. Last Friday i was making multiple changes to an ASA 5508, and had trouble with what i believe was a NAT issue. However, i had made several routing and interfaces changes at this time as well. I had full connectivity and 90% of what i wanted to do was working, but ended up rebooting all of the equipment to revert to their saved configurations, mainly because i found that the connected PC's were not taking the IP of the outside interface and instead reverting to the IP of one of the interfaces on the SD-WAN equipment we are using.
Part of my troubleshooting was to disable a bunch of NAT rules that i thought might be causing conflicts, effectively reducing the config to mirror what i know is working on the ASA we are moving some services from. After disabling the extra rules, i ran the "clear xlate" command, yet the IP of the PC's was still showing the SD-WANs IP.
Ive been looking through the running config from that day and have not been able to find why, after reducing the NAT rules to the known-working basics, confirming routing, and setting all access rules to allow any IP that night, why it still would not show the correct IP.
Aside form "clear xlate", are there some other commands i should be entering on the ASA, the 9300 series switches, or the PC's themselves, after making major configuration changes like this?
@Jesserony it's likely the traffic was unintentially translated by another NAT rule. In this instance you can run packet-tracer (CLI or ASDM) to simulate the traffic flow, this will indicate which NAT rule is being matched. You can then run "show nat detail" which will show the order of the NAT rules, you just need to ensure your new NAT rule is above the rule the traffic is matching.
Multiple Cisco Security Technologies in a single book : ASA Firepower, WSA, Umbrella, ISE and VPN with 100 percent 100 practical scenarios with 70 Labs to cover important topics of the Cisco SCOR Exam. The best part is ISE with interesting scenarios wi...
Cisco Umbrella is a big DNS service that provides not only the DNS resolution but also if the hosted website is trust or malicious, the idea behind the Layer DNS Security is that the modern attacks uses the DNS in the first step either to redirect the use...
I shared with you this detailed document I created with 27 pages about Cisco ISE Integration With F5 BIG-IP Locar Traffic Manager LTM Load Balancer for Guest Acces.
The method used for Guest Access is the Self-Registration.
Healt Monitor using HTTP...
I created an IPSEC Site to site Tunnel between two ASA Firewalls in EVE-NG topology and i want to plot the IPSEC Site to Site VPN graph on PRTG ? The SNMP Walk command is not getting any output . As the firewall is making SNMP inbound connections with the...
The purpose of this document is to demonstrate how ISE can integrate with an eduroam external server which is a WI-Fi roaming service that provides international access to devices in education, research, and higher education. Students, teachers, and resea...