Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Inbound NAT breaking existing connections

Hi all,

I need to configure an inbound nat rule on a PIX firewall so that a network that comes in through a VPN on the outside interface translates to a dmz interface (PAT).

I have the configuration in place to setup all the translation rules without the bidirectional NAT rule in place and all is working, but when I had the bidirectional nat rules:

nat (outside) 10 outside

nat (outside) 0 0 0 outside

global (dmz) 10 interface

everything breaks, even another vpn that I have running on the inside interface.

I have searched for info on bidirectional nat but the documentation available is very slim and it doesn't clearly state exactly what changes when you use it.

Can anybody give some more insigth into this?


Rodrigo Magno


Re: Inbound NAT breaking existing connections

The nat outside option lets you enable or disable outside NAT, which translates the source address of a connection coming from a lower security interface to higher interface. This feature is also called bidirectional NAT.If you enable outside dynamic NAT on an interface, then you must configure explicit NAT policy for all hosts on the interface that need to initiate connections to inside networks. If you want to translate some hosts, but not others, then use identity NAT or NAT exemption (nat 0 or nat 0 access-list) to disable address translation for these additional hosts. The norandomseq and emb_limit options are not supported with outside NAT.

Use the following url to get more info about configuring outside(bidirectional) NAT on PIX: