after finishing off with the nat statements we give clear xlate command
but where as for conn we dont give clear conn. when initiating a connection and if we see it on firewall using sh conn we can see the conn details but to see this nat info using sh xlate it takes 3 hrs by default or we can see it only if clear xlate is given..is it correct?
The "clear xlate" command allows you to manually clear the current (live) translation table. This command is useful if you configure your NAT and want to test it immediately.
By default, the translation (xlate) table is set to remain for 3 hours (so what you see was correct) before it starts to flush/refresh again (use 'show xlate" to view this table ). You can see this in your firewall config as follow:
You can also use "clear conn" to manually flush the current connection table. Bear in mind clearing xlate or connection will flush the whole active translation & connections, but useful for testing purposes.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...