Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Routing and ASA 5510

Hi hi,

Wonder if anyone can help to provide some information on how the followings can be done. thanks a lot in advance.

Current Infrastructure is as below.

ISP <--> 3825 Router <--> ASA 5510 <--> Private network and DMZ

Had configured a IPSEC/GRE tunnel on the router which comes with the IP of 10.0.0.x. This tunnel is supposed to be able to access the DMZ configured (IP 172.25.25.x) on the firewall but currently still not able to. Questions:

a. How I can allow traffic to flow from the tunnel (i.e. 10.0.0.x) on the router to the DMZ machine? Had added a route on the router to point any traffic for network to the firewall but it does not work. Also did a traceroute and found that the traffic keeps going to the internet instead of the firewall (a default route is configured to go to the internet).

b. I had removed all the NAT/PAT on the firewall so that ALL traffic can flow in and out of DMZ without the need of translation. Currently, all the traffic still does not flow through at all and there are error logs about "no translation group" happening on the firewall. Any ideas how to make the traffic free flow in and out of the DMZ?

Any help and advise on the above are greatly appreciated.

Thanks a lot,


New Member

Re: Routing and ASA 5510

Hi Tan,

Can you please provide the configuration? The "no translation group" error must mean that you're not putting in the right NAT translation/ translation exempt.