cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
741
Views
0
Helpful
3
Replies

ASA-5540 used for IPSec VPN only - can I do away with Nat 0?

jkeeffe
Level 2
Level 2

I am going to use an ASA-5540 as our VPN head-end termination device only - and not as a firewall.

Also, we have a routeable class-B address for our internal enterprise address space, so we have no need to NAT. I'd like to turn off the NAT 0 function if I can so I don't have to always add to the NAT 0 just to make sure that the 5540 does not NAT.

Is there any easy way to disable the need use NAT 0?

Are there any draw backs to doing that?

1 Accepted Solution

Accepted Solutions

yamramos.tueme
Level 1
Level 1

You can disable the use of nat 0 by disabling nat-control.

To get this done, go to global config mode and use this command:

no nat-control

To check if you have it enabled or not, you can check it with:

sh run nat-control

Cheers!

- Yamil

View solution in original post

3 Replies 3

yamramos.tueme
Level 1
Level 1

You can disable the use of nat 0 by disabling nat-control.

To get this done, go to global config mode and use this command:

no nat-control

To check if you have it enabled or not, you can check it with:

sh run nat-control

Cheers!

- Yamil

yamramos.tueme
Level 1
Level 1

You can disable the use of nat 0 by disabling nat-control.

To get this done, go to global config mode and use this command:

no nat-control

To check if you have it enabled or not, you can check it with:

sh run nat-control

Cheers!

- Yamil

yamramos.tueme
Level 1
Level 1

You can disable the use of nat 0 by disabling nat-control.

To get this done, go to global config mode and use this command:

no nat-control

To check if you have it enabled or not, you can check it with:

sh run nat-control

Cheers!

- Yamil

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: