cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Welcome to Cisco Firewalls Community


183
Views
0
Helpful
1
Replies
Highlighted
Beginner

help needed with NAT on ASA 8.4 (x)

inside: security level 100

outside: security level 0

traffic coming in from any IP address on inside interface & going out on outside interface with destination of 12.1.1.1 should be NAT'ed/PAT'ed to 100.1.1.1 IP address. How do we do it in ASA running 8.4 s/w. I'm kinda new the this new kinda NAT commands introduced in 8.3 & later.

Everyone's tags (5)
1 REPLY 1
Cisco Employee

help needed with NAT on ASA 8.4 (x)

Here we go (assuming that your inside network is 10.10.10.0/24):

object network obj-10.10.10.0

  subnet 10.10.10.0 255.255.255.0

object network obj-12.1.1.1

  host 12.1.1.1

object-network obj-100.1.1.1

  host 100.1.1.1

nat (inside,outside) source dynamic obj-10.10.10.0 obj-100.1.1.1 destination static obj-12.1.1.1 obj-12.1.1.1

It's always good to be more specific on the inside subnet, instead of using the keyword "any" as it can cause translation issue for other interfaces.