cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1897
Views
0
Helpful
9
Replies

How to translate CLI NAT lines into ASDM usage

Howdy all,

 

I am unfamiliar with Cisco NATting, and the Cisco CLI more specifically.

I have to add the following via the ASDM;

 

--> nat (Inside,Telus) source static DSG-Inside DSG-Inside destination static VPNPool VPNPool
--> nat (DMZ,Telus) source static Inside-DMZ Inside-DMZ destination static VPNPool VPNPool
--> nat (DMZ,Telus) source static NVR interface service NVR-RTSP-SOURCE NVR-RTSP-SOURCE
--> nat (DMZ,Telus) source static NVR interface service NVR-TCP-SOURCE NVR-TCP-SOURCE
--> nat (Telus,Telus) source dynamic VPNPool interface 

 

Would anyone be able to explain which entry goes where in this;

 

 

I have been working with a couple of you fine gents already on this, but I didn't want to muddy the original posting with too much info.

 

Thank you to any takers!!

Best Regards,

Sozo

1 Accepted Solution

Accepted Solutions

Francesco Molino
VIP Alumni
VIP Alumni
Hi

Dumb question: why not configuring these NATs over CLI directly as you already have the commands?

Let's take the first nat:
nat (Inside,Telus) source static DSG-Inside DSG-Inside destination static VPNPool VPNPool

Inside = source interface
Telus = destination interface
DSG-Inside (1st object right after the word static) = source address
DSG-Inside (2nd object after the 1st DSG-Inside object) = source address in translated packet section
VPNPool (1st object right after destination static) = destination address
VPNPool (2nd object after the 1st VPNPool object) = destination address in translated packet section.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

View solution in original post

9 Replies 9

Francesco Molino
VIP Alumni
VIP Alumni
Hi

Dumb question: why not configuring these NATs over CLI directly as you already have the commands?

Let's take the first nat:
nat (Inside,Telus) source static DSG-Inside DSG-Inside destination static VPNPool VPNPool

Inside = source interface
Telus = destination interface
DSG-Inside (1st object right after the word static) = source address
DSG-Inside (2nd object after the 1st DSG-Inside object) = source address in translated packet section
VPNPool (1st object right after destination static) = destination address
VPNPool (2nd object after the 1st VPNPool object) = destination address in translated packet section.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Salute Francesco,

The answer to your question is simply, fear :)

I am completely new to Cisco, and as such using the CLI gives me pause.

The ASDM however, I can see how to immediately revoke a change that I've made., with no chance of something hidden getting in the way.

I know Sonicwall better, which auto NAT's things for you, however in this new role, it's ASA all the way, so I'm learning.

Thank you very much for your assistance Francesco!

I will give this a shot.

Best Regards!

Brent 

Thank You Francesco, those are bulletproof instructions, I truly appreciate that :) I have written a lot of documentation in my day and thats some quality right there.

You brought the VPN rules home.

Thank you very much!

Brent.

 

Thanks.
Did you edit your part? I received a mail notification with your answer starting the same way but ending with a question and i don't see it anymore.

Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

Hi Francesco, I did edit, I figured it out, (cloning the secondary failover ISP settings which work) sorry for the confusion on that.

However our VPN access is still not working, when I go to vpn.dsgauto.ca it is supposed to prompt for anyconnect but the page just times out.

Would you be able to give me an idea as to why?

 

Thank you!

Brent

I may have it figured, I will update shortly..

Thank you,

Brent

No, my idea didnt work out :) 

Do you know what I may have to change for vpn.dsgauto.ca to go live? My Rules all seem correct to me, matching the ones on the secondary ISP which work.

Though this seems like maybe a DNS issue? I cant see how it ties into the ASA..

Thank you again,

Best regards,

Brent

From asdm, under file menu, you can show the whole config (show running). Can you put this config into a text file and attach it to the post please? Be careful and remove all confidential data from there.

Otherwise send it to me in private message.


Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question

PM sent, thank you very much man!

Brent

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: