08-28-2014 05:16 AM - edited 03-11-2019 09:41 PM
hello all. In my DMZ environment I usually use 1-1 static nats. I currently have a need to PAT one of my DMZ boxes so that outside users connect into port 443 but translates into 8080. I did the following which in my mind would mean if traffic comes in on 443 it will get translated to 8080 but anything else it just comes on through as it's original dest port as long as there is an ACL for it. However I got the warning message in the title so I wanted to ask the community what possible side-effects there could be.
static (dmz,outside) tcp 4.4.4.4 https 172.18.13.95 8080 netmask 255.255.255.255
static (dmz,outside) 4.4.4.4 172.18.13.95 netmask 255.255.255.255
WARNING: real-address conflict with existing static
mapped-address conflict with existing static
Solved! Go to Solution.
08-28-2014 12:53 PM
Without having seen your full configuration including NAT, I would say that there is another static NAT statement that matches the IPs and ports of the NAT statement you are trying to add.
As for the consiquences of having both, If the other statement maps the translation between different interfaces and it is located higher on the NAT list, ie. it will be matched first, then you could get an incorrect result in your translation.
--
Please remember to select a correct answer and rate helpful posts
08-28-2014 06:08 AM
Hi,
I believe there shouldn't be any problem. This is just a warning message for a the overlapping NAT rule in place....
Regards
Karthik
08-28-2014 12:53 PM
Without having seen your full configuration including NAT, I would say that there is another static NAT statement that matches the IPs and ports of the NAT statement you are trying to add.
As for the consiquences of having both, If the other statement maps the translation between different interfaces and it is located higher on the NAT list, ie. it will be matched first, then you could get an incorrect result in your translation.
--
Please remember to select a correct answer and rate helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide