01-19-2004 08:25 PM - edited 03-09-2019 06:10 AM
Hi,
I would like to know if I can use multiple NAT 0 statements for the same interface e.g inside interface.
Presently I am already using a nat (inside) 0 statement with an access list. Now I want to implement a site to site vpn. So I want the new access-list also not to be natted for the vpn traffic.
Please let me know.
Thanks.
01-20-2004 05:54 AM
You can have as many as you like. You can mix and match nat 0 access-list and nat 0 ip.address.block.here subnet.mask.goes.here style statements as well
nat 0 access-list is a true nat exemption, and is probably the best practice. Its probably cleanest to maintain one access-list for use for one nat 0 command statement
01-20-2004 07:27 PM
Thanks !
Just wanted to confirm.if the following will work ?
nat (inside) 0 access-list 100
nat (inside) 0 access-list 110
nat (inside) 0 access-list 120
Regards,
01-21-2004 04:37 AM
nope, i just tested it. you can only have one nat 0 access-list statement.
01-23-2004 06:54 PM
Is there any workaround for this ?
Regards
01-24-2004 02:54 PM
write a new accesslist that combines all of the entries you wish to have nat 0 apply to
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: