cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
653
Views
0
Helpful
0
Replies

Difference between IOS vs NX-OS NAT Order of Operation

rhayashi5
Level 1
Level 1

Dear all,

 

I plan to use NX-OS N9k such as C93148GC-FXP and C93180YC-EX. (not ACI)

I have a concern Processing order of traffic when using NAT

 

Please look at follouwing URL.

IOS NAT Order of Operation is Listed.

 

[NAT Order of Operation]

https://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/6209-5.html

 

Inside-to-Outside                                                                        Outside-to-Inside

  • If IPSec then check input access list
  • decryption - for CET (Cisco Encryption Technology) or IPSec
  • check input access list
  • check input rate limits
  • input accounting
  • redirect to web cache
  • policy routing
  • routing
  • NAT inside to outside (local to global translation)
  • crypto (check map and mark for encryption)
  • check output access list
  • inspect (Context-based Access Control (CBAC))
  • TCP intercept
  • encryption
  • Queueing
  • If IPSec then check input access list
  • decryption - for CET or IPSec
  • check input access list
  • check input rate limits
  • input accounting
  • redirect to web cache
  • NAT outside to inside (global to local translation)
  • policy routing
  • routing
  • crypto (check map and mark for encryption)
  • check output access list
  • inspect CBAC
  • TCP intercept
  • encryption
  • Queueing

 

 

Even if NX-OS, Is the packet processing order same?

 

 

Best Regards,

 

Ryunosuke Hayashi

0 Replies 0
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card