Currently migrating old PIX to new ASA 8.3 and I have a question re: multiple NATs for one object group.
So I have an ASA with 4 live interfaces, inside, outside, WEBDMZ1 and WEBDMZ2.
I need all outbound connections from inside network 192.168.10.0 / 24
so object network PROD_192.168.10.0
subnet 192.168.10.0 255.255.255.0
My NAT requirements are I need to PAT all outbound to internet.
so
nat (inside,outside) dynamic interface
BUT I need to bypass NAT for any internal connections to webdmz1
nat (inside,webdmz1) static PROD_192.168.10.0
and webdmz2
nat (inside,webdmz2) static PROD_192.168.10.0
I only seem to be able to add one NAT statement per object group What am I missing ?
Would I have to create 3 network objects with identical IP info and apply each NAT statement to each ?
Any help would be appreciated.
Cheers
Dave