|
||
| KB | 0000247 | |
| Dated | 10/05/10 | |
| Revision | 0.05 | |
Cisco PIX/ASA 8.3 Command Changes
|
||
Problem |
||
I posted to a forum the other day, the poster had a problem with their VPN, basically my response was, "Your Nat statements look bizarre - what is this config from?". At this point I realised 8.3 had brought in some syntax changes. There are quite a few changes with the OS, this will touch on the things that I see on my clients firewalls so all eventualities are NOT covered. the main areas of change are NAT/PAT. Warning: Before upgrading to version 8.3 (or newer) check you have enough RAM. |
||
Solution |
||
No More NAT and Global commands.Basically there is no more global command, and we are now a lot more reliant on object groups. If you are port forwarding (Static PAT) then the dns re-write will no longer work. NAT 0 (or no nat) no longer exists.
|
||
OLD - Regular PAT - 1 External IP to many internal IP addressesNEW - Regular PAT - 1 External IP to many internal IP addresses |
||
OLD - Static PAT (Port Forwarding)NEW - Static PAT (Port Forwarding) |
||
OLD - No NAT (seen mainly - but not always - on VPN traffic)NEW - No NATNote: For a full walkthorugh on configuring VPNs with ASA version 8.3 and above see the following article: |
||
Access ListsFor as long as I can remember when you allowed access to an IP address on a PIX/ASA you allowed access to its translated IP address, NOW YOU DO NOT, you allow access to its "Pre-translation address" |
||
OLD Access List and Static NATNEW Access List and Static NAT |
||
If this post helped you, PLEASE take the time to +1 it.
Please be aware, all information is provided free, but it does cost me to have this site hosted, if I've helped you in any way, or saved you some time/cost please take time to make a donation. If you have anything to add to an article, or have an article you would like us to publish please feel free to contact PeteNetLive. (Please be aware I get a LOT of email, I cannot assist and fix everyone's problems, please do not be offended if you do not get a response). |
||
| References - Credits - Or External Links | ||
| ASA - Memory Error (Post upgrade to version 8.3) | ||









