Cisco Systems ASA Policy NAT not working at all...

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
ASA Policy NAT not working at all... K.J. 44 09-14-06
Posted by K.J. 44 on September 14, 2006, 11:58 am
Please log in for more thread options
My policy NAT does not appear to be working at all...

I was having trouble with it as seen in my previoues post

http://groups.google.com/group/comp.dcom.sys.cisco/browse_thread/thread/fa570f250a67a170

So I gave up on that approach and I change my ACL to

access-list policy_PAT_server extended permit ip host SERVER PRIVATE IP
any

nat (inside) 1 access-list policy_PAT_server
global (outside) 1 PUBLIC IP #2

my other NAT is:

nat (inside) Private Subnet (includes PCs and server)
global (outside) PUBLIC IP #1

Everything is getting translated by the second NAT statement!

Is there something wrong here?

Thanks.


Posted by K.J. 44 on September 14, 2006, 12:05 pm
Please log in for more thread options
okay it is working now. I had to clear out the current translations
held in the table.

Shouldn't it make the translation when I telnet PUBLIC IP #2 port 25?

I am not seeing anything when I sh xlate PUBLIC IP #2 after I telnet
and my telnet's are getting a connection time out.

I am telnetting from my router which is at the edge of my network,
there is static route pointing to the ASA and there is no outbound ACL
on the Inside interface of the router.

In my outside ASA ACL I have a permit any host PUBLIC IP #2 eq 25

Am I missing something?

K.J. 44 wrote:
> My policy NAT does not appear to be working at all...
>
> I was having trouble with it as seen in my previoues post
>
>
http://groups.google.com/group/comp.dcom.sys.cisco/browse_thread/thread/fa570f250a67a170
>
> So I gave up on that approach and I change my ACL to
>
> access-list policy_PAT_server extended permit ip host SERVER PRIVATE IP
> any
>
> nat (inside) 1 access-list policy_PAT_server
> global (outside) 1 PUBLIC IP #2
>
> my other NAT is:
>
> nat (inside) Private Subnet (includes PCs and server)
> global (outside) PUBLIC IP #1
>
> Everything is getting translated by the second NAT statement!
>
> Is there something wrong here?
>
> Thanks.


Similar ThreadsPosted
ASA Policy NAT not working at all... September 14, 2006, 11:58 am
Call transfer full consult is not working properly, blind transfer is working instead October 8, 2008, 8:04 pm
PIX Policy-NAT October 17, 2005, 10:50 am
Policy NAT October 15, 2007, 9:06 am
GRE & Policy Routing July 28, 2005, 8:46 am
Service Policy October 13, 2005, 7:41 am
ASA Policy NAT Question September 14, 2006, 9:12 am
Traffic policy. October 2, 2006, 9:04 am
Cisco 877 - Policy Map December 11, 2006, 1:59 pm
IOS Upgrading "Policy" November 20, 2007, 9:33 pm
qos policy and ip sla integration February 7, 2008, 3:55 am
Question about NAT (maybe need to use policy NAT)? June 30, 2008, 6:09 pm
policy routing on PIX October 10, 2008, 9:37 am
Simple QoS Policy On 877 October 24, 2008, 10:59 am
pix policy nat small oddity July 12, 2005, 2:07 pm