ASA 8.4 - Static NAT - Problem with outbound SMTP

Answered Question
Mar 31st, 2011

Below is the interesting part of my config.  I have static NAT configured and working inbound for the Exchange Server and the Barracuda, however outbound traffic from those hosts comes out as the interface IP.  Thoughts?  I've tried a number of things (outside, inside), etc...  No luck.  Any help would be appreciated.

object network obj_any

subnet 0.0.0.0 0.0.0.0

object network DSN-EXCH01

host 10.250.231.51

object network MAIL-IN

host 10.250.231.50

!

access-list outside_inside extended permit tcp any host 10.250.231.51 eq https

access-list outside_inside extended permit tcp any host 10.250.231.51 eq www

access-list outside_inside extended permit tcp any host 10.250.231.50 eq smtp

!

nat (inside,outside) source dynamic any interface

!

object network obj_any

nat (inside,outside) dynamic interface

object network DSN-EXCH01

nat (inside,outside) static xxx.xxx.xxx.25

object network MAIL-IN

nat (inside,outside) static xxx.xxx.xxx.26

!

access-group outside_inside in interface outside

I have this problem too.
0 votes
Correct Answer by shrsunda about 3 years 2 weeks ago

Hi,

The issue here is with the order of NAT rules in the 8.4 version.

A Manual NAT rule takes precedence over Auto NAT (within object group).

So, nat (inside,outside) source dynamic any interface; is taking precedence when going from inside to outside.

I hope this helps.

-Shrikant

PS: Please mark the question resolved, if it has been answered. Do rate helpful posts. Thanks

  • 1
  • 2
  • 3
  • 4
  • 5
Average Rating: 5 (1 ratings)
Correct Answer
shrsunda Thu, 03/31/2011 - 11:09

Hi,

The issue here is with the order of NAT rules in the 8.4 version.

A Manual NAT rule takes precedence over Auto NAT (within object group).

So, nat (inside,outside) source dynamic any interface; is taking precedence when going from inside to outside.

I hope this helps.

-Shrikant

PS: Please mark the question resolved, if it has been answered. Do rate helpful posts. Thanks

clamasters Thu, 03/31/2011 - 11:52

That makes sense, thank you. Is there a better way to acomplish this then?  I see there are some options to insert rules before and after other parts of NAT but not sure what to use just yet.

Thank you,


Curtis

clamasters Thu, 03/31/2011 - 11:56

Actually, I just removed that part of the config since I already had an object NAT configured for 0.0.0.0.

Thank you very much.

Actions

Login or Register to take actions

This Discussion

Posted March 31, 2011 at 9:10 AM
Stats:
Replies:3 Avg. Rating:5
Views:3514 Votes:0
Shares:0
Tags: nat, asa_8.4
+

Related Content

Discussions Leaderboard

Rank Username Points
1 7,861
2 6,140
3 3,170
4 1,473
5 1,446