cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2652
Views
0
Helpful
6
Replies

NAT: Where to implement it.

zappo0305
Level 1
Level 1

Im planning to rollout NAT on our network.

Are there any best practices when comes to implement NAT?

and where is the best place to implement NAT: on the firewall or on the Internet router?

Cheers

6 Replies 6

Anu M Chacko
Cisco Employee
Cisco Employee

Hi,

You should implement NAT on the gateway device of your network. So, say, if your ISP connects to the firewall, you will should configure NAT on the firewall.

When you implement NAT, it would be best if you translate all your internal IP addresses to public IP addresses using NAT. 

Here is a guide on how to implement NAT on an ASA:

http://www.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_control.html

Let me know if you have more queries.

Regards,

Anu

my gateway is the 4500 , the firewall sitting behind the 4500.

Would it be more secure implement NAT on the firewall?

I know the definition of NAT and how it works.

Any recommendations would be greatly appreciated.

So your ISP connects to the 4500.   Is there a specific reason why you have the 4500 outside and the firewall on the inside?

Having an internal firewall to protect the internal network? and the 4500 to do routing?

ANy  more tips any 1?

I would suggest you put your firewall outside of the 4500 and configure NAT on the firewall. Or else, you can configure NAT on the 4500 but then, having or not having the firewall does not really make a difference.

sir.vegaskid
Level 1
Level 1

Hi,

is there any reason why you dont want to use the firewall as a router also? e.g. routing performance requirements? Most setups I see do have the router outside the firewall, else just a firewall.

Not sure what Anu means by his last comment as firewalls offer much more protection that just NAT. ACLs, packet inspection to name just two.

Review Cisco Networking products for a $25 gift card