Cisco ASA NAT Error

Answered Question
Jul 24th, 2008
User Badges:

Hi,


In my ASA I am getting some error when I want to configure static NAT and NAT exempt configuration. I think Some miss configuration has been done.

The error msg given below..

Firewall-ASA-02(config)# static (inside,outside) x.x.x.12 10.138.77.54 netma$

INFO: Global address overlaps with NAT exempt configuration


Firewall-ASA-02(config)# no access-list nonat extended permit ip 10.138.77.0 255.$

INFO: Outside address overlap with static NAT configuration


Plz help to reslove this issue..why i am getting this type of error msg.


Regards,

som


Correct Answer by Marwan ALshawi about 8 years 11 months ago

as i see ur config the following line not sure if u need it if not try to REMOVE it and let me know


access-list nonat extended permit ip any 10.138.77.192 255.255.255.224


i think the following one too, !


access-list nonat extended permit ip any 10.138.74.64 255.255.255.192


good luck and let me know

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Marwan ALshawi Thu, 07/24/2008 - 21:53
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

can u post ur nat config or show run ?

Marwan ALshawi Fri, 07/25/2008 - 00:52
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

ok

now with these config dose the ASA working ok?

and when u get this errors?

can u put the lines that u wanna add and u getting errors when adding them



somnath21 Fri, 07/25/2008 - 01:00
User Badges:

Hi,


I am getting error whnever I try to add a new STATIC NAT and NAT EXEMPT.

plz find the eeror msg..


Firewall-ASA-02(config)# static (inside,outside) x.x.x.25 10.138.77.62 netmask 255.255.255.255

INFO: Global address overlaps with NAT exempt configuration



INHYD-ASA-02(config)#access-list nonat extended permit ip 10.138.77.0 255.255.255.0 10.10.15.0 255.255.255.0

INFO: Outside address overlap with static NAT configuration



Regerds,

som


Correct Answer
Marwan ALshawi Fri, 07/25/2008 - 01:15
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

as i see ur config the following line not sure if u need it if not try to REMOVE it and let me know


access-list nonat extended permit ip any 10.138.77.192 255.255.255.224


i think the following one too, !


access-list nonat extended permit ip any 10.138.74.64 255.255.255.192


good luck and let me know

somnath21 Fri, 07/25/2008 - 01:40
User Badges:

Hi


I have removed this two lines but same error msg coming.I am getting the same error msg during removing aslo and after removing when tried to add a new exempt.



Marwan ALshawi Fri, 07/25/2008 - 01:44
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

remove them

save ur config

reload then try again

u have to reload after changing nat and nat policies

somnath21 Fri, 07/25/2008 - 02:26
User Badges:

Hi,


Thanx!


Its working now without error.


Regards,

som

Marwan ALshawi Fri, 07/25/2008 - 02:35
User Badges:
  • Purple, 4500 points or more
  • Community Spotlight Award,

    Best Publication, December 2015

iam glad it working :)

Actions

This Discussion