When using no nat control on a FWSM, I would assume that the xlate table (sh xlate) should be empty.
Is this correct as I am seeing some one to one entries in the xlate. I am not seeing every single host, only approx 200 out of 5000 potential hosts.
Can someone confirm this ?
By default, the FWSM creates NAT sessions for all connections even if you do not use NAT. To avoid running into the maximum NAT session limit, you can disable NAT sessions for untranslated traffic (called xlate bypass).
To enable xlate bypass, enter the following command: