We would like to block/filter all DNS NAT entries on a VRF from reaching the NAT Logger server.
Current Config:
ip nat log translations flow-export v9 udp destination 172.X.X.X 999 source Loopback0
ip nat log translations flow-export v9 vrf XX on
The NAT command reference says:
To enable high speed logging for all or some a Network Address Translation (NAT) translations, use the ip nat log translations flow-export command in global configuration mode. To remove one or more translations from the log, use the no form of this command.
ip nat log translations flow-export v9 {udp destination addr port source interface interface-number | {vrf-name | global-on}}
no ip nat log translations flow-export v9 {udp destination addr port source interface interface-number | {vrf-name | global-on}}
But when I use <no ip nat log translations flow-export v9 udp destination 172.X.X.X 53 source int Loopback0> the logging is disabled completely!
Can any one provide some configs/advice on how this can be done?
Thank You!