Cisco Cisco ASA 5515-X Adaptive Security Appliance - No Payload Encryption Installation Guide
35
Cisco ASA 5500 Migration to Version 8.3
OL-22176-01
NAT Migration
NAT Migration Messages
Some NAT configurations cannot be migrated automatically, or are slightly different from the original
configuration.
configuration.
lists error messages you might see, and information about the messages.
Table 14
NAT Migration Messages
Message and Description
Error Message The following 'nat' command didn't have a matching 'global' rule on interface '<name>'
and was not migrated.
and was not migrated.
Explanation
Missing global command. If a nat command does not have a matching global command, the nat command
will be removed and will not be migrated.
Recommended Action
If you intended to have a matching global command, you will need to recreate the configuration
using the new NAT commands.
Example:
Old Configuration
nat (dmz) 1 10.1.1.0 255.255.255.0
Migrated Configuration
Not migrated.
Error Message Alias command was migrated between interfaces ‘any’ and ‘inside’ as an estimate.
Explanation
alias command migration. The alias command is applied between same and lower security level interfaces.
After migration, the rules are added between a given interface and any. This is semantically different as the new rule
applies to all interfaces including itself.
applies to all interfaces including itself.
Recommended Action
This is relatively safe to migrate and needs no attention in most cases. See the
for an example migration.
Example:
Old Configuration
alias (inside) 209.165.200.225 192.168.100.10
Migrated Configuration
object network obj-192.168.100.10
host 192.168.100.10
nat (any,inside) static 209.165.200.225 dns