08-05-2013 10:46 AM - edited 03-11-2019 07:21 PM
Hi All,
We have 3 sections of NAT
1>Manual NAT
2>Auto NAT
3>Manual NAt after Auto.
Lets say on ASA we config Manual and Auto Nat.
Now Order of NAT is
1>Manual
2>Auto
If i move the Manual NAT to section 3 of NAT which is Manual NAT after auto NAT.
Now Order of NAT is
2>Auto
3>Manual NAT after Auto.
Now when i try to do Process Manual NATafter auto section number 3 it does not work as it hits Auto NAt and does not go down.
Need to know the reason behind this?
Regards
MAhesh
Solved! Go to Solution.
08-05-2013 10:52 AM
Hi Mahesh,
Essentially the main order of the NAT is this
When for example traffic from your LAN comes to the ASA the ASA will go through your NAT conrfigurations in order from Section 1 to Section 2 to Section 3 UNTIL a match is found for the connection according to its source/destination IP/port.
So what your are seeing is that you have atleast 2 NAT rules that match the same connection attempt and after you move a Section 1 Manual NAT to Section 3 Manual NAT that means that some NAT configuration/rule in Section 2 is now probably matching the traffic and therefore the Section 3 Manual NAT is not matched anymore. This is simply because of the above mentioned ordering/priority of the NAT rules/configurations.
- Jouni
08-05-2013 10:57 AM
Also as a little side note,
There is also difference in the ordering of the NAT configurations depending on the Section
So in a nutshell. You can manually set the order of the Manual NAT rules but Auto NAT rules are ordered automatically by the ASA itself.
You can see the current order of the Auto NAT rules with the command
show nat
- Jouni
08-05-2013 10:52 AM
Hi Mahesh,
Essentially the main order of the NAT is this
When for example traffic from your LAN comes to the ASA the ASA will go through your NAT conrfigurations in order from Section 1 to Section 2 to Section 3 UNTIL a match is found for the connection according to its source/destination IP/port.
So what your are seeing is that you have atleast 2 NAT rules that match the same connection attempt and after you move a Section 1 Manual NAT to Section 3 Manual NAT that means that some NAT configuration/rule in Section 2 is now probably matching the traffic and therefore the Section 3 Manual NAT is not matched anymore. This is simply because of the above mentioned ordering/priority of the NAT rules/configurations.
- Jouni
08-05-2013 10:56 AM
Thanks Jouni
I got it now
Best reagrds
MAhesh
08-05-2013 10:57 AM
Also as a little side note,
There is also difference in the ordering of the NAT configurations depending on the Section
So in a nutshell. You can manually set the order of the Manual NAT rules but Auto NAT rules are ordered automatically by the ASA itself.
You can see the current order of the Auto NAT rules with the command
show nat
- Jouni
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide