09-09-2009 07:53 AM - edited 03-11-2019 09:13 AM
Cisco document says by default traffic from higher level interface to lower level interface is always allowed. However it seems for traffic going from higher interface to lower interface, ASA always checks xlate table first. So there should always be some type of NAT (pool or static) or PAT configured from higher interface to lower interface.
Is it correct?
Thanks
09-09-2009 08:02 AM
Yes that is correct. Here's an example NAT from 'outside' to 'inside'
static (inside,outside) 75.50.95.72 10.10.5.65 netmask 255.255.255.255
Hope that helps.
09-09-2009 08:30 AM
You don't always need to nat the source - you can also use nat bypass or nat exemption, but this still has to be configured.
There is also an option to negate the use of NAT totally - the no nat-control command, however I recommend you fully understand this command before you use it.
09-09-2009 06:35 PM
Thanks all. I'm clear now. I just didn't find it clearly specified in any Cisco documentations.
I've never tried "no nat-control".
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide