09-25-2015 06:18 AM - edited 03-11-2019 11:39 PM
Hello,
I wanted to know meaning of below NAT command in Csico ASA Version 8.3(2)
nat (inside outside) source static any any
Is NAT happening here or No translations
Regards
Rajkumar
09-25-2015 08:29 AM
Hi,
Ideally, it should not be like this.
You cannot do a static NAT using any any.
We can use dynamic NAT if inside users want to go to the internet.
nat (inside,outside) dynamic any interface.
Regards,
Pulkit Saxena
09-25-2015 09:10 AM
Hi,
I have seen this config in one of the my customer Firewall.
Not sure wether NAT is happening or not
nat (GI6/0.170,GI5/0.180) source static any any
nat (GI5/0.180,GI6/0.170) after-auto source static any any
When I see show nat , I see the counter is incresing on contineous basis.
2 (GI6/0.170) to (GI5/0.180) source static any any
translate_hits = 0, untranslate_hits = 434791714 --------> this counter is chnaging
09-25-2015 09:53 AM
Hi,
It does a self NAT (identity NAT).
So for example, 1.1.1.1 is getting translated to 1.1.1.1 only.
Regards,
Pulkit Saxena
09-28-2015 11:20 AM
Hi,
Is there any specific reason for this NAT in your config?
This NAT rule is as good as doing no translation at all. It is going to match all the traffic which does not match any other NAT statement.
It will make ASA do more processing, if it is not required then you can remove it.
Thanks,
R.Seth
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide