Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

No NAT - Cannot see the outside (ASA 7.x)

Used the ADSM to create a startup config.

Since we are not using NAT do I have to create an route from the Outside interface to the Inside interface.

  • Firewalling
19 REPLIES

Re: No NAT - Cannot see the outside (ASA 7.x)

What are your security-levels set too? If they are different, you will still need NAT.

nat (inside,outside) 10.0.0.0 10.0.0.0 netmask 255.0.0.0

If they are the same, try

same-security-traffic permit inter-interface

HTH

New Member

Re: No NAT - Cannot see the outside (ASA 7.x)

Thanks! I will give a look.

Outside is Sec Lev 0 and Inside is Sec Lev 100

New Member

Re: No NAT - Cannot see the outside (ASA 7.x)

i have the following commands:

static (Inside,Outside) host1 host1 netmask 255.255.255.255

...

static (Inside,Outside) hostn hostn netmask 255.255.255.255

I saw a note about "no nat-control", I know I don't have it in the config.

Re: No NAT - Cannot see the outside (ASA 7.x)

I'm new to NAT-Control, but it sounds like it would work since you have public addresses on the inside. Let us know how it works if you choose to use it.

PIX 7.0 introduces the nat-control command. You can use the nat-control command in configuration mode in order to specify if NAT is required for outside communications. With NAT control enabled, configuration of NAT rules is required in order to allow outbound traffic, as is the case with previous versions of PIX software. If NAT control is disabled (no nat-control), inside hosts can communicate with outside networks without the configuration of a NAT rule. However, if you have inside hosts that do not have public addresses, you still need to configure NAT for those hosts.

New Member

Re: No NAT - Cannot see the outside (ASA 7.x)

Thanks I am reading up on it now.

New Member

Re: No NAT - Cannot see the outside (ASA 7.x)

Thanks I am reading up on it now.

Cisco Employee

Re: No NAT - Cannot see the outside (ASA 7.x)

Please refer the below URL for configuration details:

PIX/ASA 7.x: Enable/Disable Communication Between Interfaces

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml#Same

Regards,

Arul

** Please rate all helpful posts **

Silver

Re: No NAT - Cannot see the outside (ASA 7.x)

In version 6.x code, you will need this:

static (i,o) inside_net inside_net netmask /x

In Pix version 7.x code, the default is

"no nat-control". In other words, Pix will

route traffic just like router out of the

box.

However, ACL is still needed to go from low

to high.

CCIE security

New Member

Re: No NAT - Cannot see the outside (ASA 7.x)

I saw this command this morning. I will give it a try.

727
Views
0
Helpful
19
Replies