Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

4
  • Hmm, the command errors as it is depreciated, I am running 8.4.2 Commented Sep 13, 2016 at 20:33
  • After 8.3 there is no nat-control. So you should configure nat exemption. Here is how you can achieve that: object network LOCAL_LAN subnet 11.11.11.0 255.255.255.192 object network REMOTE_LAN subnet 11.11.11.64 255.255.255.252 nat (dmz,outside) source static LOCAL_LAN LOCAL_LAN destination static REMOTE_LAN REMOTE_LAN Commented Sep 13, 2016 at 20:47
  • Thank Nuran, that is as far as I got however I can't specify "any" as the REMOTE_LAN?? for example what if it is 11.11.11.11 to 8.8.8.8, how do I ensure no nat control is happening? Commented Sep 14, 2016 at 12:31
  • So apparently i didn't assign my outside ACL to my outside interface via access-group command. I figured it out when I did a packet-tracer and it kept saying it was denied by ACL. Thanks for your help. Commented Sep 14, 2016 at 13:24