Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Access Lists for VPN and VPN Client

Hi.

After creating a LAN2LAN VPN OR a VPN client connection, of couse, an access list is created. One entry for the access list is for the NAT0. In the line shown below, it is for the VPN CLIENT IP POOL. My question is WHY whenever I do a 'sh access-list' command, all NAT0 entries in all access lists have "0 hits." It does not seem to make sense. And, how can I change that?

THANKS!!!!!!

John

access-list INSIDE_nat0_outbound line 1 extended permit ip any 10.1.100.0 255.255.255.0 (hitcnt=0)

3 REPLIES

Re: Access Lists for VPN and VPN Client

John,

Generically - the device does not log hits on NAT acl's.

HTH>

New Member

Re: Access Lists for VPN and VPN Client

Hi!! Thanks for responding. So, I guess there's no way to tell if a NAT rule is being hit as packets traverse the firewall? :(

John.

Cisco Employee

Re: Access Lists for VPN and VPN Client

Yes, this is documented in the command reference.

Access list hit counts, as shown by the show access-list command, do not increment for NAT exemption access lists.

Please refer the below URL for details:

http://www.cisco.com/en/US/docs/security/asa/asa72/command/reference/no_72.html

Regards,

Arul

** Please rate all helpful posts **

135
Views
9
Helpful
3
Replies