cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
395
Views
0
Helpful
1
Replies

Needs help on NAT

kope
Level 1
Level 1

global (outside) 2 interface

nat (inside) 2 access-list dmz

access-list dmz permit ip 21.21.0.0 255.255.0.0

nat (inside) 0 0.0.0.0 0.0.0.0

static(inside,outside) 3.3.3.0 3.3.3.0 netmask 255.255.255.0

static(inside,outside) 3.3.4.0 3.3.4.0 netmask 255.255.255.0

.......

The problem here is I am unable to translate the 21.21.0.0 network to its global interface address.

Is the nat (inside) 0 0.0.0.0 0.0.0.0 the cause for not able to translate? Is it safe to remove this command?

thanks,

1 Reply 1

Julio Carvajal
VIP Alumni
VIP Alumni

Hello Kope,

Yes, that is the cause of the issue, please remove it!

Removing this you will start making translation from the inside of your ASA, that is all that is going to change.

Regards,

Do rate helpful posts

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
Review Cisco Networking for a $25 gift card