no-NAT scenario with ASA as vpn endpoint--help!

Unanswered Question
Mar 12th, 2009

I'm setting up a pair of ASA firewalls that will exclusively be used as VPN endpoints for about 75 tunnels. All traffic passing through it will be VPN traffic, to which none of it needs to be NAT'd. I'm running version 8.x on the ASAs. Nat-control is disabled. My question is, without the need to NAT, do I have to put in any no-nat config or will the ASA simply pass the traffic as is? And if I am required for a no-nat statement, is below what I need to make it work:

access-list no-nat permit ip any any

nat (inside) 0 access-list no-nat

I don't want to add any unnessary config. Can anyone verify for sure whether or not I need to do anything?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
Ivan Martinon Thu, 03/12/2009 - 20:02

Without nat-control you should not have a problem as long as there is no nat statements at all, your nat statement however should be ok in case you need it.

Actions

This Discussion