cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1226
Views
0
Helpful
5
Replies

ASA NAT based on source network

MICHAEL KENNEDY
Level 1
Level 1

I have a question regarding the merging of 2 networks and NAT. The networks and interface names have been changed to simplify the diagram below.

The 192.168.0.0 network has never used a NAT translation to connect to the server 1.1.1.1. The 172.17.0.0 network used to sit on another interface which required NAT and has been moved.

Can I create a NAT translation based on a network range?

I have resolved this issue by using a NAT exemption for the 192.168.0.0 network but I like the flexibility NAT based on the source network (Checkpoint NAT is configured in this way).

Thanks in advance

NAT-Based-On-Network.jpg

5 Replies 5

f00f1ter
Level 1
Level 1

Which version of code on the ASA?

On which interface does 172.17.0.0/16 terminate?

The code version is 8.05. 172.17.0.0/16 was an external network to a third party but has been brought onto the corporate network on the inside interface. The 192.168.0.0/24 was always a trusted network and didn't require NAT. The server sits on our DMZ.

If this was a new network connection we would not use NAT but there are so many applications from the 172.17/16 range using the NAT address that this is not viable.

tarekaljallad
Level 1
Level 1

You can create a NAT entry for 1.1.1.1 and then restrict by access list to source network. That will NAT it for everything talking to it through the outside (of which ever interface 172.17.0.0 is plugged into) interface.

Sounds like what I am looking for. Can you point me in the right direction for examples or documentation?

If the 172.17.0.0 is behind your inside interface, then you do not need NAT between it and 1.1.1.1 in your DMZ, simply make sure the ASA has the proper route to 172.17.0.0 in your internal network.

This might help:

http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807fc191.shtml

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card