cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
589
Views
0
Helpful
7
Replies

ACL in NAT

Rupesh Kashyap
Level 1
Level 1

Hi, I have Natted Inside traffic on Pix. I have opened ACL- NTP traffic from Inside n/w to permit reacg Outside NTP Servers. My question is, Should I open the Returned NTP traffic too (From Outside) OR no need to open reverse traffic in NAT/PAT.

7 Replies 7

sdoremus33
Level 3
Level 3

If its no trouble could you post additional config info pertaining to the ASA

ACL(s)

NAT control commands

static translations, and so on... Thanks

global (outside) 12 200.200.200.30 netmask 255.255.255.255

nat (inside) 12 10.0.0.0 255.0.0.0

access-group from_inside in interface inside

Access-list from_inside permit udp10.0.0.0 255.0.0.0 any eq 123

My Question is, You can see the ACL on inside interface. There is no any acl on Outside interface. Should I open the same returning port on OUtside interface also or no ACL is required for returning traffic with NAT ???

Rupesh,

That's fine. No need to allow return traffic back to the public ip address. As long as internal hosts who originate ntp (request)packets first. That's why it's called state-full.

HTH,

Toshi

Thanks boss. I got it. I appreciate you all.

Hi, I tested 3 routers (A->B->C). It is not working--

1. I applied NAT (Overload) on router B.

2. I initiated Ping from A to C & I am able to.

3. Now I have applied ACL on Outside interface on B to deny all traffic from outside on B.

4. After Step 3, I am not getting Ping reply on A.

My question is, why replied ICMP on B is blocked with ACL. It should bypass, as From inside, it is allowed.

Rupesh,

Good question.ICMP is stateless protocol.

You need to allow "echo-reply" on ACL from outside to inside on B.

Toshi

Sounds good. I would do it. Beside this, I would initiate TCP Telnet command from A for C & would update you, if returned traffic would not blocked by Outside ACL.

I will post u on tomorrow.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card