Re: ASA Policy NAT not working at all...



okay it is working now. I had to clear out the current translations
held in the table.

Shouldn't it make the translation when I telnet PUBLIC IP #2 port 25?

I am not seeing anything when I sh xlate PUBLIC IP #2 after I telnet
and my telnet's are getting a connection time out.

I am telnetting from my router which is at the edge of my network,
there is static route pointing to the ASA and there is no outbound ACL
on the Inside interface of the router.

In my outside ASA ACL I have a permit any host PUBLIC IP #2 eq 25

Am I missing something?

K.J. 44 wrote:
My policy NAT does not appear to be working at all...

I was having trouble with it as seen in my previoues post

http://groups.google.com/group/comp.dcom.sys.cisco/browse_thread/thread/fa570f250a67a170

So I gave up on that approach and I change my ACL to

access-list policy_PAT_server extended permit ip host SERVER PRIVATE IP
any

nat (inside) 1 access-list policy_PAT_server
global (outside) 1 PUBLIC IP #2

my other NAT is:

nat (inside) Private Subnet (includes PCs and server)
global (outside) PUBLIC IP #1

Everything is getting translated by the second NAT statement!

Is there something wrong here?

Thanks.

.



Relevant Pages

  • Re: Static Translations Disappearing
    ... this router and see if they have the same behavior. ... you are running into a NAT bug. ... It wouldn't hurt to change IOS and ... ....where it just shows all translations being dynamic (0 static, ...
    (comp.dcom.sys.cisco)
  • Re: Static Translations Disappearing
    ... I bought a Cisco 837 ADSL router a couple of months ago, ... I'm having though is that static translations I've configured in the ... I've been logging NAT translations out to syslog and this has ... encapsulation aal5mux ppp dialer ...
    (comp.dcom.sys.cisco)
  • Re: Static Translations Disappearing
    ... I'm having though is that static translations I've configured in the ... I've been logging NAT translations out to syslog and this has ... encapsulation aal5mux ppp dialer ... I looked at the source ports the system was using for outbound TCP ...
    (comp.dcom.sys.cisco)
  • Re: 2610 Nat or problem with browsing web
    ... Let me start by saying I'm online and NAT is ... MISSES and EXPIRED TRANSLATIONS increase. ... service timestamps debug datetime msec ... Create a ~256KB in memory logging buffer ...
    (comp.dcom.sys.cisco)
  • Re: telnet to SCO 5.0.6 as vmware guest - network blues
    ... Using vmware NAT option: ... All outbound from SCO works great. ... I can telnet to SCO from the vmware-server host OK, ... Any port opened by a machine behind a NAT gateway is translated into ...
    (comp.unix.sco.misc)