cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
543
Views
0
Helpful
3
Replies

Another NAT question.....

louis0001
Level 6
Level 6

Hi,

I have an OUTSIDE interface (goes to another private network 10.1.1.254/24)

On the INSIDE interface (192.168.200.0/24) we have various servers. These are statically natted to a different ip eg 10.1.1.1 > 192.168.200.1, 10.1.1.2 > 192.168.200.10 etc

There is no dynamic nat from the INSIDE to the OUTSIDE or no global nat set.

I now need to add a DMZ (172.31.1.1/24) with dynamic NAT to the OUTSIDE. Will this break the static nat's (on the INSIDE interface) already in place?

1 Accepted Solution

Accepted Solutions

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

There is also IOS Firewall.

You can add a dynamic NAT for just the DMZ to the outside interface without breaking the existing static NAT (assuming the IP addresses don't overlap anywhere).

View solution in original post

3 Replies 3

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

It would help if you could at least say what kind of device you have.  Cisco 800 series running IOS, Cisco ASA 5505 running 8.4(7), etc.

Could you post your current NAT configuration?

Sorry, Because I posted in firewalling I assumed it would be an ASA. It's an ASA 5510 running 8.2

Philip D'Ath
Meraki Community All-Star
Meraki Community All-Star

There is also IOS Firewall.

You can add a dynamic NAT for just the DMZ to the outside interface without breaking the existing static NAT (assuming the IP addresses don't overlap anywhere).

Review Cisco Networking for a $25 gift card