Make a PayPal Donation


  KB 0000247
  Dated 10/05/10
  Revision 0.05
   

Cisco PIX/ASA 8.3 Command Changes
{NAT / Global / Access-List}

Problem

 

I posted to a forum the other day, the poster had a problem with their VPN, basically my response was, "Your Nat statements look bizarre - what is this config from?". At this point I realised 8.3 had brought in some syntax changes. There are quite a few changes with the OS, this will touch on the things that I see on my clients firewalls so all eventualities are NOT covered. the main areas of change are NAT/PAT.

Warning: Before upgrading to version 8.3 (or newer) check you have enough RAM.

Solution

 

No More NAT and Global commands.

Basically there is no more global command, and we are now a lot more reliant on object groups.

If you are port forwarding (Static PAT) then the dns re-write will no longer work.

NAT 0 (or no nat) no longer exists.

 

OLD - Regular PAT - 1 External IP to many internal IP addresses

NEW - Regular PAT - 1 External IP to many internal IP addresses

OLD - Static PAT (Port Forwarding)

NEW - Static PAT (Port Forwarding)

OLD - No NAT (seen mainly - but not always - on VPN traffic)

NEW - No NAT

Note: For a full walkthorugh on configuring VPNs with ASA version 8.3 and above see the following article:

Cisco ASA Site to Site VPN from CLI

Access Lists

For as long as I can remember when you allowed access to an IP address on a PIX/ASA you allowed access to its translated IP address, NOW YOU DO NOT, you allow access to its "Pre-translation address"

OLD Access List and Static NAT

NEW Access List and Static NAT

 

If this post helped you, PLEASE take the time to +1 it.

Please be aware, all information is provided free, but it does cost me to have this site hosted, if I've helped you in any way, or saved you some time/cost please take time to make a donation.

If you have anything to add to an article, or have an article you would like us to publish please feel free to contact PeteNetLive. (Please be aware I get a LOT of email, I cannot assist and fix everyone's problems, please do not be offended if you do not get a response).

References - Credits - Or External Links
ASA - Memory Error (Post upgrade to version 8.3)

 


powered by
Socialbar