[Contents] [Prev] [Next] [Index] [Report an Error] [No Frames]


Monitoring NAT

This section explains how to view NAT license information, NAT statistics, NAT translation entries, NAT address pool information, and NAT inside and outside rule settings.

Displaying the NAT License Key

The show license nat command displays the NAT license key.

show license nat

Displaying Translation Statistics

The show ip nat statistics command displays internal statistics that apply to NAT operation.

show ip nat statistics

Displaying Translation Entries

The show ip nat translations command displays current translations that reside in the translation table.

Simple translation entries appear with inside/outside and local/global address information. Extended entries appear with added protocol and port numbers (or query IDs).

Using verbose mode additionally provides the time since creation and time since last use for each translation entry.

show ip nat translations

host1#show ip nat translations
Prot    Inside local      Inside global     Outside global   Outside local
----    ---------------   ---------------   --------------   ----------------
GRE     13.1.2.1:*        20.0.0.1:*            ---               ---
ICMP    13.1.2.2:4        20.0.0.2:4            ---               --- 
TCP     13.1.2.3:20       20.0.0.3:50           ---               ---

NOTE: Because they are not NAPT translations, port numbers for GRE translations appear as asterisks (*).

host1#show ip nat translations verbose
                                                          Time         Time
                    Inside      Outside     Outside      since        since
Prot Inside local   global      global       local      creation     last use
---- ------------ ----------- ----------- ----------- ------------ ------------
     20.0.0.3     30.0.0.3    ---         ---         00:04:50     00:00:01
     21.0.0.3     30.208.0.3  ---         ---         00:02:12     00:00:01
     21.0.0.4     30.208.0.4  ---         ---         00:02:12     00:00:01
     ---          ---         50.0.0.3    70.0.0.3    00:03:24     Never
     ---          ---         51.0.0.3    70.208.0.3  00:01:44     00:00:01
     ---          ---         51.0.0.4    70.208.0.4  00:01:44     00:00:01
UDP  ---          ---         50.50.0.3:8 70.50.0.3:8 00:03:10     Never
                              7           108
UDP  22.0.0.4:63  30.224.0.3: ---         ---         00:02:12     00:00:01
                  4097
UDP  22.0.0.3:63  30.224.0.3: ---         ---         00:02:12     00:00:01
                  4096
TCP  ---          ---         50.50.0.3:8 70.50.0.3:8 00:03:10     Never
                              0           008
UDP  20.50.0.3:87 30.50.0.3:8 ---         ---         00:03:35     Never
                  108

Displaying Address Pool Information

The show ip nat pool command displays NAT address pool information. The command output displays configuration (mask and address ranges) of all address pools, unless you supply a specific pool name.

show ip nat pool

Displaying Inside and Outside Rule Settings

The show ip nat inside rule and show ip nat outside rule commands display access list and pool usage for all dynamic translation rules configured for the virtual router. If you do not specify an access list, the output displays address pool associations for each of the access lists for either inside or outside translation rules in the virtual router. Specifying an access list filters the output to display only the address pool associated with the specified list.

show ip nat inside rule

show ip nat outside rule


[Contents] [Prev] [Next] [Index] [Report an Error] [No Frames]