cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
342
Views
5
Helpful
1
Replies

ASA 5525 NAT logic: connection initiator source matters here?

Hello.

"object network SERVER1
nat (dmz,Outside) static 1.1.1.1"

If the connection is initiated from the Outside to the DMZ , and the Outside ACL allows this traffic, will this circuit connect, or will it fail because there is needed an additional NAT rule?

Thank you.

1 Accepted Solution

Accepted Solutions

@jmaxwellUSAF that'll work. Traffic sent to the nat ip of 1.1.1.1 will be untranslated to the private IP address of the DMZ server.

You'd obviously need an ACE in the ACL to the private (real) IP address of the server to permit the traffic.

View solution in original post

1 Reply 1

@jmaxwellUSAF that'll work. Traffic sent to the nat ip of 1.1.1.1 will be untranslated to the private IP address of the DMZ server.

You'd obviously need an ACE in the ACL to the private (real) IP address of the server to permit the traffic.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card