cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
445
Views
5
Helpful
1
Replies

ASA 5525 NAT logic: connection initiator source matters here?

Hello.

"object network SERVER1
nat (dmz,Outside) static 1.1.1.1"

If the connection is initiated from the Outside to the DMZ , and the Outside ACL allows this traffic, will this circuit connect, or will it fail because there is needed an additional NAT rule?

Thank you.

1 Accepted Solution

Accepted Solutions

@jmaxwellUSAF that'll work. Traffic sent to the nat ip of 1.1.1.1 will be untranslated to the private IP address of the DMZ server.

You'd obviously need an ACE in the ACL to the private (real) IP address of the server to permit the traffic.

View solution in original post

1 Reply 1

@jmaxwellUSAF that'll work. Traffic sent to the nat ip of 1.1.1.1 will be untranslated to the private IP address of the DMZ server.

You'd obviously need an ACE in the ACL to the private (real) IP address of the server to permit the traffic.

Review Cisco Networking for a $25 gift card