cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2427
Views
0
Helpful
6
Replies

Cisco ASA & NAT for UDP

RS19
Level 4
Level 4

I have a application behind Cisco ASA & the application uses UDP.

The client connects to the application using UDP port & there is 2 ASA firewall between the client & the application server.

 

ASA 1 does the source NAT

ASA 2 does the destination NAT

 

Let me know if UDP traffic works with NAT & it not what is the alternate or work around ?

6 Replies 6

generally speaking yes unless the application has something in the payload
to check the source IP then it will fail.


**** please remember to rate useful posts

thanks.

You mean to say NAT can be used for UDP traffic. Let me know if my understanding is right.

 

The only thing I need to check is if the application looks for the original IP address in the payload ?

If it does not look for the source IP in the payload  then it should work.

If you have any doc or link as reference please share.

Any input

Hi,

 

   Yes, it's supported and it's gonna work for 99.9% of the cases. What is the application you are running over UDP? Here's some samples for object NAT, you will be using UDP service instead of TCP service:

 

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/115904-asa-config-dmz-00.html

 

Regards,

Cristian Matei.

Thanks. The application is attendance punching. Do u have any example with UDP NAT

Hi,

 

 Assuming you run minimum 8.3 code on the ASA, here's some guides to help you out, if you get stuck, provide details:

 

https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/115904-asa-config-dmz-00.html

https://www.cisco.com/c/en/us/support/docs/ip/network-address-translation-nat/118996-config-asa-00.html

 

Regards,

Cristian Matei.

Review Cisco Networking for a $25 gift card