cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

146
Views
0
Helpful
0
Replies
Highlighted
Beginner

NAT on Same Interface

Hi,

 

My application group want to want to access application hosted in same subnet via it's NATted IP address.

 

Source: 10.10.10.1

Destination: 10.10.10.2

NAT: 30.30.30.30

 

 

Firewall have only two zone outside and inside.

 

Both source and destination IP located in same subnet and application group access this application which is hosted in 10.10.10.2 from source host 10.10.10.1 through using url (external DNS map with 30.30.30.30 and natted with 10.10.10.2).

 

This communication is not working in below configuration.

 

obj-10.10.10.0

subnet 10.10.10.0 255.255.255.0

object network source

host 10.10.10.2

nat (inside,outside) static 30.30.30.30 

 

nat (inside,outside) after-auto source dynamic obj-10.10.10.0 interface

 

access-list acl_inside extended permit tcp any4 any4 eq 80

access-list acl_inside extended permit tcp any4 any4 eq 443

 

access-list acl_outside extended permit tcp any4 10.10.10.2 eq 80

access-list acl_outside extended permit tcp any4 10.10.10.2 eq 443

 

route outside 0.0.0.0 0.0.0.0 30.30.30.254

 

can we configure like this to resolve this issue:

object network source-in

host 10.10.10.2

nat (inside,inside) static 30.30.30.30