cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1213
Views
0
Helpful
3
Replies

Cisco ASA both NAT and PAT

nlg-networks123
Level 1
Level 1

Hi experts.

 

I have a Cisco ASA 5515 where we have several static NAT's, some from the DMZ to outside, and some from inside to outside.

 

I have a requirement to configure PAT for some inside to outside traffic, however I am nervous of affecting the existing 1-1 NATs.

 

Using the ASDM I can select the source address range, however for the destination I find the ASA will not accept the object as an FQDN, it needs to be a specified address range.

Also of note is proxy-arp is enabled which I understand is helpful for the NAT function?

 

Hoping for some good general advice - I don't have a test environment so am a little nervous!

 

With regards

 

Dave

 

 

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

that is normal in most of the FW config, that is standard every organization.

 

We need to only need to look place the Right NAT Rule in right order with out breaking the live system.

So suggest to post the config, and explain the goal of the IP you like to PAT. so we can look and suggest best we can.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

use the section 3 of the NAT.

 

it would be some thing like this.

 

object network INSIDE

 subnet 192.168.1.0 255.255.255.0

nat (inside,outside) after-auto source dynamic any interface

please do not forget to rate.

GRANT3779
Spotlight
Spotlight

If you wanted to get a clear understanding on the order of NATs for ASA there is a great document that can be found here that will hopefully answer any queries you have. It was put together by @Jouni Forss and will help visualise the NAT types and order they are processed etc. It is very good.

 

https://community.cisco.com/t5/security-documents/asa-nat-8-3-nat-operation-and-configuration-format-cli/ta-p/3143050

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: