The difference between Identity NAT and NAT Exemption
December 6, 2011
Leave a comment
According to the Cisco ASA: All-in-One Firewall, IPS, and VPN Adaptive Security Appliance book, “The main difference between identity NAT and NAT exemption is that with identity NAT, the traffic must be sourced from the address specified with the nat 0 statement, whereas with NAT exemption, traffic can be initiated by the hosts on either side of the security appliance. NAT exemption is a preferred method to bypass traffic when it is flowing over a VPN tunnel.”
So, what does this mean really?
Read more…
Categories: CCNP Security, Cisco ASA 8.2