?
Solved

No Nat Control

Posted on 2009-02-08
1
Medium Priority
?
1,118 Views
Last Modified: 2012-08-14
We have an ASA 5540.  I issued the command "sh run nat-c" and it comes back "no nat control'.  From my understanding this means that traffic should pass through the firewal w/o nat transaltion.  The problem is that I couldn't ping from one subnet to antoher, and the subnets are out different interfaces on the ASA.  As soon as I put in a nat exempt statement in the ASA on the source interface it worked fine.  Why would this be if the "no nat control" command is issued??  Thanks for your help.
0
Comment
Question by:jiggin23
1 Comment
 
LVL 32

Accepted Solution

by:
rsivanandan earned 500 total points
ID: 23590844
It probably meant that you don't have either nat command or nat exclusion. One thing to remember is that even if you want to have 'non-natted' services, you need to nat it. What it means is, nat it to the same ip.

2 ways of getting around it. Say you have an ip 1.1.1.1 which you don't want to nat, then you still nat it, but you nat it to itself, or include a nat exclusion command. Both works the same way.

First -> static (inside, outside) 1.1.1.1 1.1.1.1 netmask 255.255.255.255

Second -> nat exclusion which you obviously know.

Cheers,
Rajesh
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
This Micro Tutorial will teach you how to add a cinematic look to any film or video out there. There are very few simple steps that you will follow to do so. This will be demonstrated using Adobe Premiere Pro CS6.
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Suggested Courses

807 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question