cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
406
Views
9
Helpful
3
Replies

Access Lists for VPN and VPN Client

netsec123
Level 1
Level 1

Hi.

After creating a LAN2LAN VPN OR a VPN client connection, of couse, an access list is created. One entry for the access list is for the NAT0. In the line shown below, it is for the VPN CLIENT IP POOL. My question is WHY whenever I do a 'sh access-list' command, all NAT0 entries in all access lists have "0 hits." It does not seem to make sense. And, how can I change that?

THANKS!!!!!!

John

access-list INSIDE_nat0_outbound line 1 extended permit ip any 10.1.100.0 255.255.255.0 (hitcnt=0)

3 Replies 3

andrew.prince
Level 10
Level 10

John,

Generically - the device does not log hits on NAT acl's.

HTH>

Hi!! Thanks for responding. So, I guess there's no way to tell if a NAT rule is being hit as packets traverse the firewall? :(

John.

Yes, this is documented in the command reference.

Access list hit counts, as shown by the show access-list command, do not increment for NAT exemption access lists.

Please refer the below URL for details:

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/no_72.html

Regards,

Arul

** Please rate all helpful posts **

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: