cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
342
Views
0
Helpful
2
Replies

dual homed ASA is using both NAT/PAT addresses

Wan_Whisperer
Beginner
Beginner

So I have an ASA Dual homed using IP SLA with tracking for my routes to set outside1 as the primary link:

 


nat (any,outside1) after-auto source dynamic Internal interface
nat (any,outside2) after-auto source dynamic Internal interface

route outside1 0.0.0.0 0.0.0.0 XXX.XXX.54.XXX 1 track 1
route outside2 0.0.0.0 0.0.0.0 XXX.XXX.108.XXX 254

 

 

The issue is that somehow a few devices are getting NATted to XXX.XXX.108.XXX (outside2)

 

How can I prevent devices from NATting to outside2 unless outside1 is down?

 

 

Thanks for your help!

 

 

2 Replies 2

balaji.bandi
VIP Community Legend VIP Community Legend
VIP Community Legend

The issue is that somehow a few devices are getting NATted to XXX.XXX.108.XXX (outside2)

 

i beiieve you should use below syntax for the backup route

 

route backup 0.0.0.0 0.0.0.0  XXX.XXX.108.XXX 254

 

refer below guide :

 

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/118962-configure-asa-00.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Cristian Matei
Collaborator
Collaborator

Hi,

 

   Maybe at some point the SLA went down and thus routing/NAT changed? For those IP's which get NAT'ed by the second NAT statement, run a "packet-tracer" and see which route/NAT entry does it match.

 

Regards,

Cristian Matei.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers