10-02-2020 12:38 PM
I have an IKEV2 tunnel that I'm trying to configure. My problem is that when I introduce NAT into the mixture on the initiating ASA(Away1asa), the tunnel doesn't build. When I remove NAT the tunnel will build. When I have NAT in the mix and I send interesting traffic it's as if the policy isn't in use. As proof of that I look at the debug output from the router that I have that sits between the two ASA's and it sends a reply back to the initiating ASA that says that the destination host is unreachable, stating that the IP address it's trying to reach is the internal LAN address of the Headend/Robot ASA. I've tried it with and without NAT Exemption on the profile. Can some one please assist.
Solved! Go to Solution.
10-02-2020 12:52 PM
I imagine your existing NAT rule is being matched before your NAT exemption rule. Recreate the NAT rule with "after-auto" command, this will move this NAT rule to "Section 3" and apply last, ensuring traffic will match the NAT exemption rule. Try this:-
Away1
no nat (inside,outside) source dynamic away-Net1 interface
nat (inside,outside) after-auto source dynamic away-Net1 interface
Robotasa
no nat (inside,outside) source dynamic LocalNet interface
nat (inside,outside) after-auto source dynamic LocalNet interface
HTH
10-02-2020 12:52 PM
I imagine your existing NAT rule is being matched before your NAT exemption rule. Recreate the NAT rule with "after-auto" command, this will move this NAT rule to "Section 3" and apply last, ensuring traffic will match the NAT exemption rule. Try this:-
Away1
no nat (inside,outside) source dynamic away-Net1 interface
nat (inside,outside) after-auto source dynamic away-Net1 interface
Robotasa
no nat (inside,outside) source dynamic LocalNet interface
nat (inside,outside) after-auto source dynamic LocalNet interface
HTH
10-02-2020 01:02 PM
OOOOOOOOOOOOOH MY GOSH!!!!! I've been punching walls and kicking chairs for a week on this problem. Thanks Rob. That fixed my issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide