Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Static NAT issue

I have just installed my first FWSM at one of your internet pops. Pretty simple only inside and outside no dmz (all listed below). I had to put a static address translation so the internet router could talk back into the internal syslog and tacacs servers on the internal network ( / which works fine for the connections allowed inbound from the internet router. But when I try to access the internet from those two devices its not being routed because the pix is using the static address ( / to the internet router and it is not being routed after that. I know I can do an address translation to another one of my address and this will work but I am trying to get around this because I have another Internet POP soon to change from Firewall-1 to PIX that will literally have 100(s) of these static address translations.


global (outside) 1 netmask

global (outside) 2 netmask

global (outside) 3 netmask

global (outside) 4 netmask

global (outside) 5 netmask

global (outside) 6 netmask

global (outside) 7 netmask

global (outside) 8 netmask

global (outside) 9 netmask

nat (inside) 1 0 0

nat (inside) 2 0 0

nat (inside) 3 0 0

nat (inside) 4 0 0

nat (inside) 5 0 0

nat (inside) 6 0 0

nat (inside) 7 0 0

nat (inside) 8 0 0

nat (inside) 9 0 0

static (inside,outside) netmask 100 100

static (inside,outside) netmask 100 100


Thanks for any help.


Re: Static NAT issue


For routing to the inetnet a public address is must. Either do translation on the FWSM or on the edge router.

You can try to make NAT0 work here

e.g. access-list 101 permit ip

nat (inside) 0 access-list 101

So it will be a translation only between the TWO IPs.

If the inside server wants to go to internet, it will be using NAT/Global



Re: Static NAT issue

Nadeem thank you for the reply. But if the Edge router has to talk back to the inside server (say for AAA) won't I need a static for that translation? Then the static will over ride the global translation for the internal server out to the internet. I will give your recommendation a try to see how it works thanks.




Re: Static NAT issue

so here is the deal. Either make static conditional or make nat conditional. IF you have checked this url for policy NAT, it should work for your scenario.



CreatePlease to create content