cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
113
Views
1
Helpful
3
Replies

NAT rule error and not saving after migration from ASA to FTD

Here is the original ASA rule - interfaces have been renamed 

 

nat (IG_PCH_INT_INSIDE_CHESS,IG_PCH_INT_OUTSIDE_CHESS) source dynamic ObjectGroup1 pat-pool obj-group-pat-pool flat include-reserve round-robin destination static EXTNHSMAIL EXTNHSMAIL

 

Here is the configuration in FMC

NetworkMonkey101_4-1737629113512.png

 

NetworkMonkey101_0-1737629038500.pngNetworkMonkey101_1-1737629053894.png

NetworkMonkey101_2-1737629067554.png

 

Here is the error.. 

NetworkMonkey101_3-1737629097319.png

 

How do I resolve this?

 

1 Accepted Solution

Accepted Solutions

@NetworkMonkey101 yes, create new objects using a range instead.

View solution in original post

3 Replies 3

@NetworkMonkey101 you've used a subnet in the object use for the PAT pool?

"PAT pool—Create a network object that includes a range, or create a network object group that contains hosts, ranges, or both. You cannot include subnets." https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/740/management-center-device-config-74/interfaces-settings-nat.html#ID-2090-0000044f

 

Yep two subnets in the NAT pool. So recreate and use a range instead of the subnet..

NetworkMonkey101_0-1737630088393.png

 

@NetworkMonkey101 yes, create new objects using a range instead.

Review Cisco Networking for a $25 gift card