cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2971
Views
0
Helpful
6
Replies

Dual NAT with ASA 8.2

Karam Hanna
Level 1
Level 1

Hi,

i am trying to configure Dual NAT (source and destination) with multiple subnets in the source, i am trying to figure out how to accomplish this with 8.2 ASA , can anyone help please

Original source 

172.21.113.0/24

10.233.0.0/24

10.229.19.0/24

Original destination

10.1.1.1/32

translated source

208.65.111.1/32

translated destination        

192.168.1.1/32

1 Accepted Solution

Accepted Solutions

Sorry, outbound NAT should be dynamic

access-list NET1 ext permit ip 172.21.113.0 255.255.255.0 host 192.168.1.1

access-list NET1 ext permit ip 10.233.0.0 255.255.255.0 host 192.168.1.1

access-list NET1 ext permit ip 10.229.19.0 255.255.255.0 host 192.168.1.1

access-list NET2 ext permit ip host 10.1.1.1 host 208.65.111.1

nat (inside) 5 access-list NET1

global (outside) 5 208.65.111.1

static (outside,inside) 192.168.1.1 access-list NET2

View solution in original post

6 Replies 6

Peter Koltl
Level 7
Level 7

Believe me, it will be much easier to configure it with 8.3 twice NAT.

Anyway, which side is outside and which is inside?

thanks Peter,

i wish if i can upgrade to 8.3 but i don't have the option,source is behind the inside and destination is behind the outside

access-list NET1 permit ip 172.21.113.0 255.255.255.0 host 192.168.1.1

access-list NET1 permit ip 10.233.0.0 255.255.255.0 host 192.168.1.1

access-list NET1 permit ip 10.229.19.0 255.255.255.0 host 192.168.1.1

access-list NET2 permit ip host 10.1.1.1 host 192.168.1.1

Correction:

access-list NET2 permit ip host 10.1.1.1 host 208.65.111.1

static (inside,outside) 208.65.111.1 access-list NET1

static (outside,inside) 192.168.1.1 access-list NET2

whew...

I assume 192.168.1.1 is the mapped address that inside hosts will see and 10.1.1.1 is the real address in the outside zone.

Table 12  lists source and destination NAT migration examples.

Peter,

i am getting this error for NET1

ERROR: access-list used in static has different local addresses

Sorry, outbound NAT should be dynamic

access-list NET1 ext permit ip 172.21.113.0 255.255.255.0 host 192.168.1.1

access-list NET1 ext permit ip 10.233.0.0 255.255.255.0 host 192.168.1.1

access-list NET1 ext permit ip 10.229.19.0 255.255.255.0 host 192.168.1.1

access-list NET2 ext permit ip host 10.1.1.1 host 208.65.111.1

nat (inside) 5 access-list NET1

global (outside) 5 208.65.111.1

static (outside,inside) 192.168.1.1 access-list NET2

thank you Peter, it works like a charm, much appreciated

Review Cisco Networking products for a $25 gift card