Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NAT on ASA not working, leading to Clientless VPN failing

Cisco Adaptive Security Appliance Software Version 8.3(1)

Device Manager Version 6.3(1)

I have a Cisco ASA5520 that I have setup to allow a GRE tunnel through from a router at site B. This all works fine when I use the below NAT with associated router object on the inside

object network SWTEST

nat (inside,outside) static interface

My problem comes in that this kills off my Cleintless VPN connection to the same firewall, I changed my NAT to point at another of my statically assigned IP addresses, and then nothing works. Can anyone help with what I've done wrong, or what i should do? My rule base allows any GRE in from the source, and rules all look fine

I'm guessing that I should do the below, but it doesn't work

object network SWTEST

nat (inside,outside) static 195.224.23.23

Thanks alot

Stuart

  • Firewalling
Everyone's tags (4)
1 ACCEPTED SOLUTION

Accepted Solutions

NAT on ASA not working, leading to Clientless VPN failing

Hello Stuart,

Did you clear the xlate table, conn table and the local-host table after making the changes

Configuration looks fine, please do a packet tracer like this:

packet-tracer input outside tcp 4.2.2.2 1025 195.224.23.23 80

I think our next step would be to do captures.

Regards,

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com
2 REPLIES

NAT on ASA not working, leading to Clientless VPN failing

Hello Stuart,

Did you clear the xlate table, conn table and the local-host table after making the changes

Configuration looks fine, please do a packet tracer like this:

packet-tracer input outside tcp 4.2.2.2 1025 195.224.23.23 80

I think our next step would be to do captures.

Regards,

Looking for some Networking Assistance? Contact me directly at jcarvaja@laguiadelnetworking.com I will fix your problem ASAP. Cheers, Julio Carvajal Segura http://laguiadelnetworking.com
New Member

NAT on ASA not working, leading to Clientless VPN failing

Hi jcarvaja,

That worked. Clearing the tables was succesful. Thanks alot for your help on this. Sorry it's taken a while to get back to you.

Stuart

414
Views
0
Helpful
2
Replies