07-27-2012 04:29 AM - edited 03-11-2019 04:35 PM
Hello,
I use ton setup some ASA55xx but with the new version, i don't arrive to see some sample config on the CCO for help me to configure.
8.2 or 8.3 config can't be upgraded to 8.6 ???
I begin to read the CLI 8.6 config but ...... not very clear for me ....
simple config with Dmz,web server and some static !!!!
ASA 8.0 be so simple .... than 8.3 or up ....
I don t see lot of people use 55x. Normal ?
07-28-2012 08:25 PM
Hi Bro
When you do an incremental upgrade from 8.2 --> 8.3 --> 8.4 --> 8.6, the configuration in the ASA will auto-convert for you. If it doesn't you could paste your 8.2 config, and we can assist you to convert it to 8.6 :-)
07-28-2012 10:54 PM
Hi Fulbert,
Your config changes from 8.2 to 8.3 will have some issues in getting that converted especially with the NAT commands.
8.3 to 8.6 will not have any issues in the conversion. Most of the command set will be same
except few like NAT commands. The below sample of NAT will be helpful for you in distinguising between older OS and the newer OS.
Please do rate if the given information helps.
Static NAT/PAT
Pre-8.3 NAT | 8.3 NAT |
Regular Static NAT static (inside,outside) 192.168.100.100 10.1.1.6 netmask 255.255.255.255 | object network obj-10.1.1.6 |
Regular Static PAT static (inside,outside) tcp 192.168.100.100 80 10.1.1.16 8080 netmask 255.255.255.255 | object network obj-10.1.1.16 |
Static Policy NAT access-list NET1 permit ip host 10.1.2.27 10.76.5.0 255.255.255.224 static (inside,outside) 192.168.100.100 access-list NET1 | object network obj-10.1.2.27 host 10.1.2.27 |
Pre-8.3 NAT | 8.3 NAT |
Regular Dynamic PAT nat (inside) 1 192.168.1.0 255.255.255.0 | object network obj-192.168.1.0 |
Regular Dynamic PAT nat (inside) 1 10.1.2.0 255.255.255.0
| object network obj-10.1.2.0 |
Regular Dynamic PAT-3 nat (inside) 1 0 0 | object network obj_any |
Dynamic Policy NAT object-group network og-net-src | object network obj-192.168.100.100 |
Policy Dynamic NAT (with multiple ACEs) access-list ACL_NAT permit ip 172.29.0.0 255.255.0.0 | object network obj-172.29.0.0 object network obj-192.168.2.0 object network obj-192.168.3.0 object network obj-192.168.4.0 nat (inside,outside) source dynamic obj-172.29.0.0 obj-192.168.100.100 |
Outside NAT global (inside) 1 10.1.2.30-1-10.1.2.40 | object network obj-10.1.2.27 |
NAT & Interface PAT together nat (inside) 1 10.1.2.0 255.255.255.0 | object network obj-192.168.100.100_192.168.100.200 |
NAT & Interface PAT with additional PAT together nat (inside) 1 10.0.0.0 255.0.0.0 global (outside) 1 192.168.100.1-192.168.100.200 global (outside) 1 interface global (outside) 1 192.168.100.210 | object network obj-192.168.100.100_192.168.100.200 |
Static NAT for a Range of Ports Not Possible - Need to write multiple Statements or perform a Static one-to-one NAT | (in) (out) 10.1.1.1-------ASA----- --xlate-------> 10.2.2.2 Original Ports: 10000 - 10010 Translated ports: 20000 - 20010
service tcp source range 10000 10010
service tcp source range 20000 20010
host 10.1.1.1 object network server-xlate host 10.2.2.2
|
76551 Views
By
Karthik
11-22-2012 12:53 PM
And what about this old command that permit inside to dmz without translation ?
static (inside,dmz) 192.168.0.0 192.168.0.0 netmask 255.255.0.0
?
11-22-2012 04:47 PM
object network Inside_subnet
network 192.168.0.0 255.255.255.0
nat (inside,dmz) source static Inside_subnet Inside_subnet
Regards,
Remember to rate all of the helpful posts and mark the question as answered
Julio
04-16-2015 03:47 AM
Hi thanks
i have problem regarding nat below is the path of the discussion id. please review this and suggest the solution,
https://supportforums.cisco.com/discussion/12479686/nat-91
Thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide