Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

NAT/PAT question

I have a new firewall I am turning up. On the firewall I have 3 dmz interfaces (2 are turned up currently) and an inside interface towards the customers interanl network.

What I am attempting to do is to send traffic to the customers internal networks networks, and networks without doing any NAT.

I want to send any INET destined traffic as the PAT address using the inside interface IP of such as The DMZ source for this communication is CETCNET. I've attached a config. I was thinking a NONAT acl and NAT definition and a global definition along these lines:

object-group network ATK_PRIVATE_NETS




access-list NONAT_CETC permit ip object-group ATK_PRIVATE_NETS

access-list CETC_INET_NAT permit ip any

nat (CETCNET) 0 access-list NONAT_CETC

nat (CETCNET) 10 access-list CETC_INET_NAT

global (inside) 10 interface

But I still get the feeling I'm missing something. Version is 8.2.(5)29. Looking forward to reading any suggestions anyone might have. I like to keep it simple as possible on firewalls like this.

Everyone's tags (4)