I am trying to set a new context and want to allow ainternet ccess to users through new context...
Internetrouter<==== FWSM (Admin, context1, context 2)<=====LAN
internet router inside and outside ip is public ip...
FWSM(outside of admin context and contex1 are allocated resource vlan 15 having same public subnet assigned)
and then Router inside interface is connected to access port(VLAN15)..
Inside interface for fwsm Context 1 is vlan 68 and one pc is attached to vlan 68.
I am able to ping internet router inside ip from PC(vlan 68) but not able to nat the inside traffic..
I assigned first PAT for inside subnet of context 1 and then also tried using static NAT but when chacking sh xlate i am not able to see any traslation... it show same address..
fwsm/context1# sh xlate
1 in use, 2 most used
Global 192.168.3.234 Local 192.168.3.234
fwsm/context1# sh conn
6 in use, 15 most used
Network Processor 1 connections
UDP KPTLOUT 22.214.171.124:53 KPTL 192.168.3.234:1032 idle 0:01:46 Bytes 940 FLAGS - D
TCP KPTLOUT 126.96.36.199:21 KPTL 192.168.3.234:1549 idle 0:00:05 Bytes 132 FLAGS - s
i captured the traffic at inside interface which show the icmp traffic sending the request and getting reply on real ip..nat not working
21: 16:24:30.538159242 802.1Q vlan#68 P0 180.150.x.x > 192.168.3.234: icmp:
22: 16:24:31.538160242 802.1Q vlan#68 P0 192.168.3.234 > 180.150.x.x: icmp:
23: 16:24:31.538160242 802.1Q vlan#68 P0 180.150.x.x > 192.168.3.234: icmp:
24: 16:24:31.538160442 802.1Q vlan#68 P0 192.168.3.234 > 180.150.x.x: icmp:
159: 17:45:23.543013072 802.1Q vlan#68 P0 192.168.3.234.1544 > 188.8.131.52.21: S 23
47316862:2347316862(0) win 65535 <mss 1460,nop,nop,sackOK>
I have given NAT control also but no luck.. seems NAT is not working spl for new context...