Precedence order on ACL and NAT rules

Unanswered Question
Mar 12th, 2003

Hi All,

What is the precedence order on ACL and NAT Rules ??

I have an router that I made some NAT rules to hide some IP address.

When creating my ACL rules, I have to use the NAT'ed IP, or the original IP address ??


I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
wolfrikk Wed, 03/12/2003 - 05:13

It depends on where the ACL is going to be placed. If it is on the outside network interface, the router will see the NAT'ed IP in the packets, not your inside ip addresses. You would want your ACL to us the NAT'ed (internet IP's) in this case. If the ACL is on the inside network interface, the internal IP's would be used.

I hope that helps.


This Discussion