cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1686
Views
0
Helpful
8
Replies

NAT EXEMPT migration from 8.2 to 9.9 no-proxy-arp route-lookup

drlbaluyut
Level 1
Level 1

Hello

 

Can someone enlighten me when to append no-proxy-arp route-lookup for the identity manual NAT/NAT Exempt for 9.9? Or is there a best practice for this?

8 Replies 8

balaji.bandi
Hall of Fame
Hall of Fame

Migrating from 8.2 to 9.9 is not an straight forward, you need to look upgrade path. ( i suggest to stick your latest OS with 5 Start rating, until you have rason to go 9.9)

 

there is lot of changes from 8.2 to 8.4, so i suggest to understand the chages and make the upgrade plan accordingly.

 

https://www.cisco.com/c/en/us/td/docs/security/asa/asa83/upgrading/migrating.html

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi

 

Yes, actually i'm converting the pre8.3 to post8.4 nat configs line by line manually. I'm just confuse when to append the no-proxy-arp route-lookup for the post8.4 nat exempt

Abheesh Kumar
VIP Alumni
VIP Alumni

Hi,

For upgrading ASA from 8.2 to 9.9, you need to upgrade to 8.4 first. 

Upgrade Path

8.2(x) → 8.4(6) →9.9(x)

Please go through the release note before upgrade, there are lot of changes from 8.2 to 9.9. For identity nat ASA not required to answer the arp quires.

 

HTH

Abheesh

 

Hi @Abheesh Kumar

 

Actually i will not do an upgrade, i will replace the 8.2 firewall with a 9.9 firewall that is why i am migrating the configuration manually. So for 9.9 NAT Exempt configuration, i need to append no-proxy-arp route-lookup?

Hi,
For identity nat ASA does not act as a Proxy Server of the subnet used in the NAT statement. It should lookup the route and reach the destination. So for identity nat required no-proxy-arp route-lookup

HTH
Abheesh

Hi

What will be the impact if i don't append no-proxy-arp route-lookup? will it not reach the destination?

Hi,

Below doc can help you to understand more about proxy-arp, route-lookup are where to be used.

https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/nat_objects.html

 

HTH

Abheesh

might this link could help/make your life bit easier to you convert the pre 8.3 to post 8.4 nat

 

 https://www.tunnelsup.com/nat-converter/

please do not forget to rate.
Review Cisco Networking for a $25 gift card