Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

no-NAT scenario with ASA as vpn endpoint--help!

I'm setting up a pair of ASA firewalls that will exclusively be used as VPN endpoints for about 75 tunnels. All traffic passing through it will be VPN traffic, to which none of it needs to be NAT'd. I'm running version 8.x on the ASAs. Nat-control is disabled. My question is, without the need to NAT, do I have to put in any no-nat config or will the ASA simply pass the traffic as is? And if I am required for a no-nat statement, is below what I need to make it work:

access-list no-nat permit ip any any

nat (inside) 0 access-list no-nat

I don't want to add any unnessary config. Can anyone verify for sure whether or not I need to do anything?


Re: no-NAT scenario with ASA as vpn endpoint--help!

Without nat-control you should not have a problem as long as there is no nat statements at all, your nat statement however should be ok in case you need it.