Solved

Using Nats with Nat control off

Posted on 2007-11-21
2
803 Views
Last Modified: 2010-04-21
Is there any downside to using NATs (in particular NAT/Global combos) with Nat Controll off?  It is the default setting for the ASA and I haven't noticed any unusual behavior.  I have 6 vritual interfaces and only have the nat/global pair setup for traffic flowing from one of the 5 inside/dmz interfaces to the outside.
0
Comment
Question by:RolandCT
2 Comments
 
LVL 28

Accepted Solution

by:
Jan Springer earned 250 total points
ID: 20331400
If you're asking: is it okay that traffic between inside interfaces is not natted and the only traffic that gets natted is the traffic leaving the outside interface, then the answer is 'yes', that's preferred.

On other Cisco firewalls, I've had to disable nat between two non-outside interfaces.
0
 

Author Closing Comment

by:RolandCT
ID: 31410434
That pretty much confirms what I was seeing.  Thanks.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

When I upgraded my ASA 8.2 to 8.3, I realized that my nonat statement was failing!   The log showed the following error:     %ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows It was caused by the config upgrade, because t…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
This video discusses moving either the default database or any database to a new volume.
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now