ASA and hairpinning(redirecting of ip traffic)

Unanswered Question
Jul 10th, 2008
User Badges:

Does anyone have a solid, proven way of doing this?

I have an ASA-8.03 version with an inside interface and have another network via to the network

I setup the "permit intra-interface traffic" command and added a static route "route inside 1"

and also setup a nat (inside) 0 access-list nonat

In the nonat acl i have permit ip

Doing all this allows icmp packets to and from the given networks. But not an tcp traffic! What am I missing. Any Idea's. I have tried using different static nat statements as well with no luck. If you have ip redirects working an an ASA please let me know what you have done to accomplish this.

Thanks In Advance,

Pat B

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
acomiskey Thu, 07/10/2008 - 08:13
User Badges:
  • Green, 3000 points or more

Give this a try instead of nat 0.

global (inside) 1 interface

nat (inside) 1

May not be exactly what you want, but it should work.

srue Thu, 07/10/2008 - 08:19
User Badges:
  • Blue, 1500 points or more

nonat acl that permits ?

can you post the config?

do you have an acl applied to your inside interface?


This Discussion