cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1194
Views
0
Helpful
1
Replies

ASA NAT

Hi All,

 

What is the purpose of doing NAT for the object group towards inside,inside. The below is the sample configuration. Please explain on this.

 

nat (inside,inside) source static obj-10.242.69.0 obj-203.99.33.65 destination static Obj_202.89.3.8_32 Obj_202.89.3.8_32

 

Thanks.

 

1 Accepted Solution

Accepted Solutions

Alan Ng'ethe
Level 3
Level 3

See this thread:

Nat Hairpin

 


Hello,

 

Hairpin NAT is totally supported on ASA with of course the same-security-traffic command. For e.g you would like all your internal USERS  to acess an INTERNAL website with its EXTERNAL IP, then you can do a static (in,in) netmask 255.255.255.255.

 

In most cases, where you would like to do such kind of Hairpinning, you need to be mindful of the ASYMMETRIC ROUTING issues. But we have workarounds for them as well..

 

Thanks,

 

Vijaya

 


I would think its some kind of NAT to make an internal server with a public IP accessible to the 10.242.69.0 network

Remember to rate helpful posts and/or mark as a solution if your issue is resolved.

View solution in original post

1 Reply 1

Alan Ng'ethe
Level 3
Level 3

See this thread:

Nat Hairpin

 


Hello,

 

Hairpin NAT is totally supported on ASA with of course the same-security-traffic command. For e.g you would like all your internal USERS  to acess an INTERNAL website with its EXTERNAL IP, then you can do a static (in,in) netmask 255.255.255.255.

 

In most cases, where you would like to do such kind of Hairpinning, you need to be mindful of the ASYMMETRIC ROUTING issues. But we have workarounds for them as well..

 

Thanks,

 

Vijaya

 


I would think its some kind of NAT to make an internal server with a public IP accessible to the 10.242.69.0 network

Remember to rate helpful posts and/or mark as a solution if your issue is resolved.
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card