cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
374
Views
0
Helpful
3
Replies

Another NAT question.....

louis0001
Level 3
Level 3

Hi,

I have an OUTSIDE interface (goes to another private network 10.1.1.254/24)

On the INSIDE interface (192.168.200.0/24) we have various servers. These are statically natted to a different ip eg 10.1.1.1 > 192.168.200.1, 10.1.1.2 > 192.168.200.10 etc

There is no dynamic nat from the INSIDE to the OUTSIDE or no global nat set.

I now need to add a DMZ (172.31.1.1/24) with dynamic NAT to the OUTSIDE. Will this break the static nat's (on the INSIDE interface) already in place?

1 Accepted Solution

Accepted Solutions

There is also IOS Firewall.

You can add a dynamic NAT for just the DMZ to the outside interface without breaking the existing static NAT (assuming the IP addresses don't overlap anywhere).

View solution in original post

3 Replies 3

Philip D'Ath
VIP Alumni
VIP Alumni

It would help if you could at least say what kind of device you have.  Cisco 800 series running IOS, Cisco ASA 5505 running 8.4(7), etc.

Could you post your current NAT configuration?

Sorry, Because I posted in firewalling I assumed it would be an ASA. It's an ASA 5510 running 8.2

There is also IOS Firewall.

You can add a dynamic NAT for just the DMZ to the outside interface without breaking the existing static NAT (assuming the IP addresses don't overlap anywhere).

Review Cisco Networking for a $25 gift card