"No translation group found"

Unanswered Question
Oct 7th, 2009
User Badges:
  • Blue, 1500 points or more

I have an ASA 5540, running 8.0 software.

Interface "IN" (security level 100) has subnet directly connected

Interface "OUT" (security level 100) has a route to

Interface VPN (Security level 50) is for VPN clients to connect into. VPN Clients are issued addresses from a pool of

I want the ASA to NAT all requests from any VPN client going out *either* IN or OUT interfaces.

The ASA appears to be NATing traffic going out the IN interface, but not the OUT interface. Syslog shows the message:

No translation group found for tcp src VPN:10.0.1.x/y dst OUT:

My NAT commands are:


global (IN) 1 interface

global (OUT) 1 interface

nat (VPN) 0 access-list VPN_nat0_outbound

nat (VPN) 0 access-list VPN_nat0_outbound_1 outside

nat (VPN) 1 outside

nat (VPN) 0 access-list IN_nat0_outbound

What am I doing wrong ?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)


This Discussion