Appendix K Router Platform User Interface Reference

 

 

NAT Policy Page

 

Table K-7

NAT Dynamic Rule Dialog Box (Continued)

 

 

Do Not Translate VPN

This setting applies only in situations where the NAT ACL overlaps the

Traffic (Site-to-Site

crypto ACL used by the site-to-site VPN. Because the interface performs

VPN only)

 

NAT first, any traffic arriving from an address within this overlap would get

 

 

translated, causing the traffic to be sent unencrypted. Leaving this check box

 

 

selected prevents that from happening.

 

 

When selected, address translation is not performed on VPN traffic.

 

 

When deselected, the router performs address translation on VPN traffic in

 

 

cases of overlapping addresses between the NAT ACL and the crypto ACL.

 

 

Note We recommend that you leave this check box selected, even when

 

 

performing NAT into IPsec, as this setting does not interfere with the

 

 

translation that is performed to avoid a clash between two networks

 

 

sharing the same set of internal addresses.

 

 

Note This option does not apply to remote access VPNs.

 

 

 

OK button

 

Saves your changes locally on the client and closes the dialog box.

 

 

Note To save your changes to the Security Manager server so that they are

 

 

not lost when you log out or close your client, click Save on the

 

 

source page.

 

 

 

 

NAT Page—Timeouts Tab

Use the NAT Timeouts tab to view or modify the default timeout values for PAT (overload) translations. These timeouts cause a dynamic translation to expire after a defined period of non-use. In addition, you can use this page to place a limit on the number of entries allowed in the dynamic NAT table and to modify the default timeout on all dynamic translations that are not PAT translations.

Note For more information about the Overload feature, see NAT Dynamic Rule Dialog Box, page K-13.

Navigation Path

Go to the NAT Policy Page, page K-3, then click the Timeouts tab.

 

 

User Guide for Cisco Security Manager 3.2

 

 

 

 

 

 

OL-16066-01

 

 

K-15

 

 

 

Page 15
Image 15
Cisco Systems OL-16066-01 appendix NAT Page-Timeouts Tab