02-13-2024 11:54 PM
hi,
i have 2 private IP that would need to configure to a NAT pool of /29 public IP.
can someone confirm if below config is correct?
do i need to add the "flat" keyword to "PAT" using 1024-65535 dynamic ephemeral ports or this is automatic?
will both private IP range "exhaust" all PAT ports on the first IP 200.1.1.1 before going to the next IP 200.1.1.2 and so on?
object network OBJ-PUBLIC-IP-POOL
range 200.1.1.1 200.1.1.6
object network OBJ-10.0.0.16-29
subnet 10.0.0.16 255.255.255.248
nat (inside,outside) source dynamic OBJ-PUBLIC-IP-POOL
object network OBJ-10.2.0.0-16
subnet 10.2.0.0 255.255.0.0
nat (inside,outside) source dynamic OBJ-PUBLIC-IP-POOL
02-14-2024 06:11 AM - edited 02-14-2024 06:29 AM
For flat'
If for example there are more than 1000 hosts connect to Inside and all hosts use same known l4 port then using non-flat can exhaust NAT' so solution only for this case use flat NAT.
I see note in cisco doc. Before I will share it here
MHM
02-14-2024 06:19 AM - edited 02-14-2024 07:21 AM
can someone confirm if below config is correct?
The syntax is not correct, when you use the source keyword you need both the real and NATed objects defined in the NAT statement. The way you have it configured now will place the statement into manual NAT / Section 1. Dynamic NAT/PAT statements should be placed in Auto NAT / Object NAT or after-auto NAT.
object network OBJ-PUBLIC-IP-POOL
range 200.1.1.1 200.1.1.6
object network OBJ-10.0.0.16-29
subnet 10.0.0.16 255.255.255.248
nat (inside,outside) after-auto source dynamic OBJ-10.0.0.16-29 OBJ-PUBLIC-IP-POOL
object network OBJ-10.2.0.0-16
subnet 10.2.0.0 255.255.0.0
nat (inside,outside) after-auto source dynamic OBJ-10.2.0.0-16 OBJ-PUBLIC-IP-POOL
do i need to add the "flat" keyword to "PAT" using 1024-65535 dynamic ephemeral ports or this is automatic?
I have never had to use the "flat" keyword, and have had this setup in some large companies without any issues. So, I would say you do not need it.
will both private IP range "exhaust" all PAT ports on the first IP 200.1.1.1 before going to the next IP 200.1.1.2 and so on?
Unless you configure round-robin, all ports for the first public IP will be exhausted before moving on to the next IP in the range.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide