Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

MS NLB with ASA 8.2


Please find the attached diagram.

Exchange  servers are confgured for NLB, Exchange Admin explained me the mail  flow from the servers he told me that when the servers will send mail  outside they send by physical  ip and and when the  server will receive mail they will receive on NLB IP so for that reason PBR is  configured on the router for ip address which should match in  access-list and should be directed to next-hop  ISP router and static  NAT is configured on the Internet router for ip for receiving  email from outside.

The problem is neither the mails are going out nor we  are receving when i do a traceroute the packets drops at ASA nor i am  able to ping/telnet  the internet router internal ip address,when i  remove the static identity nat command from ASA i am able to ping,telnet,ssh from  the server to Internet router each and every interface and also the trace route reaches till the ISP router.

nat (insde) 1  

nat (inside)1

global (outside) 1

For receiving mail i configured the static identity NAT:

static (inside,outside) netmask


interface GigabitEthernet0/2

ip address

ip nat inside

ip virtual-reassembly

ip policy route-map Exchange

duplex auto

speed auto

ip access-list standard policy

permit log

route-map Exchange permit 10

match ip address policy

set ip next-hop ISP ROUTER

ip nat inside source static

New Member

MS NLB with ASA 8.2


Is it i am asking somthng funny, or nobody has came across to such scenario