cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2393
Views
0
Helpful
4
Replies

ASA 5505 NAT Reflection

Chi Fai Leung
Level 1
Level 1

Hi,

Our have a software must setup a public IP address to connect the inside server (assigned a inside IP address) at outside, that made the NAT on the outside ASA 5505 fw.

inside server (192.168.10.152) --- FW (NAT 1:1 192.168.10.152  <> 202.32.48.152) ---- Outside client (connect 202.32.48.152)

Now the outside client will be traversal between inside and outside and the client software will not support the DNS ... Is it possible I set the NAT Reflection on ASA 5505? Have this function on ASA 5505?

4 Replies 4

Vibhor Amrodia
Cisco Employee
Cisco Employee

Hi,

Do you want to access the Server on the Public IP from the Inside Interface ?

If yes , we can make some NAT statement which can resolve this issue.

Please let me know which version you are using on the ASA device ?

Thanks and Regards,

Vibhor Amrodia

Hi,

Yes, I want to access the Public IP address from inside interface ... the client will access 202.32.48.152 in inside, then the ASA fw should return back the 192.168.10.152 (NA reflection function) ...

My ASA 5505 version:

ASA Version: 8.2(1)
ASD Version: 6.2(1)

Hi,

So , at this moment , you would have something like this NAT configured:-

static (inside,outside) 202.32.48.152 192.168.10.152

You would need to create this statement on the ASA device:-

static (inside,inside) 202.32.48.152 192.168.10.152

Thanks and Regards,

Vibhor Amrodia

Depending on your requirements you may be able to get away with a DNS rewrite.

You have a public A record that resolves to 202.32.48.152. You have a NAT statement for 192.168.10.152 <-> 202.32.48.152. And you want to access 192.168.10.152 when you are on the inside. You can perform a DNS rewrite to cause the ASA to intercept and rewrite the DNS Answer to the query for the A record that publically returns 202.32.48.152. The ASA would rewrite 202.32.48.152 to 192.168.10.152. Your internal client would have no awareness of any of this and proceed to access 192.168.10.152.

 

I hope that helps someone.

Review Cisco Networking for a $25 gift card