@Timothy_Hall , since I am testing in my lab and it is not a router on a stick, there is no one-to-one correlation, but so far, no dice: with NAT templates disabled:
[Expert@CPCM1:0]# fwaccel stat
+---------------------------------------------------------------------------------+
|Id|Name |Status |Interfaces |Features |
+---------------------------------------------------------------------------------+
|0 |SND |enabled |eth0,eth1,eth2,eth3,eth4,|Acceleration,Cryptography |
| | | |eth5 | |
| | | | |Crypto: Tunnel,UDPEncap,MD5, |
| | | | |SHA1,3DES,DES,AES-128,AES-256,|
| | | | |ESP,LinkSelection,DynamicVPN, |
| | | | |NatTraversal,AES-XCBC,SHA256, |
| | | | |SHA384,SHA512 |
+---------------------------------------------------------------------------------+
Accept Templates : enabled
Drop Templates : disabled
NAT Templates : disabled by user
[Expert@CPCM1:0]#
...rebooted and made active cluster member.
Firewall sessions do not contain NAT data. (deleted mention of no Firewall sessions being logged, took longer to show up in the log than I expected.)
When connections are logged, they do contain NAT data, but that was the case before NAT templates were disabled.
The APCL/URLF sessions are also present in the logs, but do not contain NAT data.