Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

searching for nat translations

is there a way to search or filter for a specific nat translation instead of having to look through the whole list?

3 REPLIES

Re: searching for nat translations

Hi,

Kindly use:

router#show ip nat translations | include

Where x is the part of the line (ex: IP address) you want to filter with.

HTH, please do rate all helpful replies,

Mohammed Mahmoud.

Community Member

Re: searching for nat translations

Thanks so much. Another question:

I have found the ip address and I see a connection established to an external server, the problem in I have denied the ip address in the acl from any outside connections.

here is my acl:

access-list 101 deny ip host 10.10.10.109 any

but the nat translation shows an ipsec vpn nat-T connection on port 4500.

how do I block this?

Re: searching for nat translations

Hi,

You are always welcomed :)

This issue is due to the NAT order of operation as the output access list is checked after the NAT is done, to solve this issue, put in input access list on the LAN interface to deny the traffic when it is entered before being NATed.

http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml

HTH, please do rate all helpful replies,

Mohammed Mahmoud.

102
Views
4
Helpful
3
Replies
CreatePlease to create content