No Nat Control

Posted on 2009-02-08
Last Modified: 2012-08-14
We have an ASA 5540.  I issued the command "sh run nat-c" and it comes back "no nat control'.  From my understanding this means that traffic should pass through the firewal w/o nat transaltion.  The problem is that I couldn't ping from one subnet to antoher, and the subnets are out different interfaces on the ASA.  As soon as I put in a nat exempt statement in the ASA on the source interface it worked fine.  Why would this be if the "no nat control" command is issued??  Thanks for your help.
Question by:jiggin23
    1 Comment
    LVL 32

    Accepted Solution

    It probably meant that you don't have either nat command or nat exclusion. One thing to remember is that even if you want to have 'non-natted' services, you need to nat it. What it means is, nat it to the same ip.

    2 ways of getting around it. Say you have an ip which you don't want to nat, then you still nat it, but you nat it to itself, or include a nat exclusion command. Both works the same way.

    First -> static (inside, outside) netmask

    Second -> nat exclusion which you obviously know.


    Featured Post

    What Security Threats Are You Missing?

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Join & Write a Comment

    In this tutorial I will show you with short command examples how to obtain a packet footprint of all traffic flowing thru your Juniper device running ScreenOS. I do not know the exact firmware requirement, but I think the fprofile command is availab…
    This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
    Here's a very brief overview of the methods PRTG Network Monitor ( offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    21 Experts available now in Live!

    Get 1:1 Help Now