Solved

access list help

Posted on 2014-01-27
3
262 Views
Last Modified: 2014-02-24
what is the impact  on the traffic of the below  line


nat (inside) 0 access-list inside_nat0_outbound
0
Comment
Question by:renegadecy
  • 3
3 Comments
 
LVL 57

Expert Comment

by:Pete Long
ID: 39811585
Any traffic that is included in that access-list...........

show run access-list inside_nat0_outbound

Open in new window


will show you, is not NATTED i.e not tranlated to the public IP address, this is usually (but not always) used to stop VPN Traffic being NATTED when going to a remote site.

Pete
0
 
LVL 57

Expert Comment

by:Pete Long
ID: 39811586
To quantify, nat 0 means DONT NAT.
0
 
LVL 57

Accepted Solution

by:
Pete Long earned 500 total points
ID: 39811592
So ASA Pre 8.3 (which is in use in your example above)

nat (inside) 0 access-list EXEMPT
access-list EXEMPT extended permit ip 10.254.254.0 255.255.255.0 172.16.254.0 255.255.255.0

Open in new window

Would not tranlate any traffic going from10.254.254.0 255.255.255.0 to 172.16.254.0 255.255.255.0

This code has changed on the newer ASA's to do the same you would need,
object network obj-10.254.254.0
subnet 10.254.254.0 255.255.255.0
object network obj-172.16.254.0
subnet 172.16.254.0 255.255.255.0
nat (inside,any) source static obj-10.254.254.0 obj-10.254.254.0 destination static obj-172.16.254.0 obj-172.16.254.0

Open in new window


Pete

Cisco PIX/ASA 8.3 Command Changes {NAT / Global / Access-List}
0

Featured Post

Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
Occasionally, we encounter connectivity issues that appear to be isolated to cable internet service.  The issues we typically encountered were reset errors within Internet Explorer when accessing web sites or continually dropped or failing VPN conne…
This Micro Tutorial will teach you how to censor certain areas of your screen. The example in this video will show a little boy's face being blurred. This will be demonstrated using Adobe Premiere Pro CS6.
Video by: Mark
This lesson goes over how to construct ordered and unordered lists and how to create hyperlinks.

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now