10-03-2008 06:04 AM - edited 02-21-2020 03:58 PM
Hi.
After creating a LAN2LAN VPN OR a VPN client connection, of couse, an access list is created. One entry for the access list is for the NAT0. In the line shown below, it is for the VPN CLIENT IP POOL. My question is WHY whenever I do a 'sh access-list' command, all NAT0 entries in all access lists have "0 hits." It does not seem to make sense. And, how can I change that?
THANKS!!!!!!
John
access-list INSIDE_nat0_outbound line 1 extended permit ip any 10.1.100.0 255.255.255.0 (hitcnt=0)
10-04-2008 04:11 AM
John,
Generically - the device does not log hits on NAT acl's.
HTH>
10-04-2008 10:03 AM
Hi!! Thanks for responding. So, I guess there's no way to tell if a NAT rule is being hit as packets traverse the firewall? :(
John.
10-04-2008 12:05 PM
Yes, this is documented in the command reference.
Access list hit counts, as shown by the show access-list command, do not increment for NAT exemption access lists.
Please refer the below URL for details:
http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/no_72.html
Regards,
Arul
** Please rate all helpful posts **
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide