cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
479
Views
0
Helpful
2
Replies

Can I only NAT internal servers to the subnet of the ASA outside interface?

gwhuang5398
Level 2
Level 2

ASA's outside interface is a /24 in public address space. I also have a few different /24 public subnets that can be used for NAT. When I static NAT internal servers, do I have to NAT them to the /24 of the outside interface or can I use a difference available /24 subnet? What's the best practice when picking available public subnets for NAT?

Thanks a lot

2 Replies 2

Julio Carvajal
VIP Alumni
VIP Alumni

yes, You can also use a different public ip range from the same ISP, The ASA will proxy arp those ip addresses as well.

Regards,

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC

integreon
Level 1
Level 1

Hi,

That doesn't make any difference. You can use IP's from any pool

Anton

Sent from Cisco Technical Support iPad App

Review Cisco Networking products for a $25 gift card