cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
482
Views
5
Helpful
2
Replies

Dynamic PAT entries

keithcclark71
Level 3
Level 3

Previous engineer set these up on an ASA and I am wondering why he needed a different translation rule other than interface. Any ideas???

DynPATA.jpg

DynPATB.jpg

1 Accepted Solution

Accepted Solutions

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @keithcclark71,

Couple of reasons crosses my mind:

  • If you have multiple "outside" interfaces, e.g. two ISP providers, so you want to create redundancy in case one link fails, or if you are somehow load-balancing traffic via multiple interfaces
  • If one doesn't want to expose ASAs interface on the Internet, and to get blacklisted somewhere, or for strict separation and identification of services

Kind regards,

Milos

View solution in original post

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

not sure - aim guess one that was not working, so check the what is the content of backup.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Milos_Jovanovic
VIP Alumni
VIP Alumni

Hi @keithcclark71,

Couple of reasons crosses my mind:

  • If you have multiple "outside" interfaces, e.g. two ISP providers, so you want to create redundancy in case one link fails, or if you are somehow load-balancing traffic via multiple interfaces
  • If one doesn't want to expose ASAs interface on the Internet, and to get blacklisted somewhere, or for strict separation and identification of services

Kind regards,

Milos

Review Cisco Networking for a $25 gift card