08-13-2015 05:20 PM - edited 03-11-2019 11:25 PM
Hi,
I would like to ask how to translate/permit specific host on firewall.
on 8.2ver I used nat (inside) 1 ipofhost and subnet
on 9.2 ver it notworking?
do i need to create a net object network for the spefic address to be allow?
please see the attached file.
thank you
08-14-2015 01:31 AM
Have a look at Jounis great document on the changes from 8.2-NAT to the new NAT-model:
08-14-2015 03:12 AM
Hi Karsten,
Thanks. but based on Jounis which is better setup for my scenario? thanks
08-14-2015 03:22 AM
Configure dynamic NAT for the whole internal network (or even "any"). The rest is controlled with Access-Control-Lists.
08-14-2015 03:46 AM
Hi karsten,
But i think it's not convenient. because for example
We are using 10.1.16/24 and 10.1.17.0/24 and we only want to permit 10.1.16.1 and 10.1.17.2/24
so the rest will be configured ACL manually?
thanks
08-14-2015 03:56 AM
ACLs and not NAT are the tools for allowing and denying traffic. You should use it for what it's build. Although it was possible in older versions to handle that with NAT, it get's really complicated with actual ASA versions.
08-14-2015 04:01 AM
Thank you. I'll test all jouni sample hahahaa thanks
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide