cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
748
Views
4
Helpful
8
Replies

Simple ASA NAT question...

Hello.

May you please explain to me which ip-addresses the below ASA5525 NAT command translate to which IP-addresses?

"nat (inside,outside) source dynamic OBJECT_1"

Thank you.

1 Accepted Solution

Accepted Solutions

@jmaxwellUSAF traffic on the inside interface will be translated on the outside interface to the IP address defined in the object called "OBJECT_1".

You can use show run object from the CLI to determine the object configuration,

View solution in original post

8 Replies 8

@jmaxwellUSAF traffic on the inside interface will be translated on the outside interface to the IP address defined in the object called "OBJECT_1".

You can use show run object from the CLI to determine the object configuration,

may you please explain the same for below?

"nat (inside,outside) source dynamic OBJECT_1 interface"

Thank you!

@jmaxwellUSAF if the object "OBJECT_1" is exhausted, then translated behind the outside interface.

Each interface can PAT to around 65000 after that the PAT not work' so we add more than IP (must reachable via OUTside) to make PAT NATing 65000XIP we add

MHM

"nat (inside,outside) source dynamic OBJECT_1"

---

You say... "traffic on the inside interface will be translated on the outside interface to the IP address defined in the object called "OBJECT_1".

It seems the ASA contradicts your statement...

ASA5525# nat (inside,ouside) source dynamic ?

configure mode commands/options:
WORD Specify object or object-group name for real source.

What are your thoughts?

---

 

@jmaxwellUSAF in your first post you provided the following configuration "nat (inside,outside) source dynamic OBJECT_1", this is incorrect if applied globally, it can only be configured under an object - which was my assumption that you were referring to in my responses. What are you actually trying to achieve?

As @Rob Ingram mentioned

There are two dynamic one manual and  other is auto. 

What you use is auto which is use objects,

Here you must config object specify one IP or more. 

Both are same except the order the asa check. 

The asa check manual NAT then auto NAT

MHM

We use this to translate INside Subnet to one or more Public IP that is reachable via Outside interface.

MHM

Review Cisco Networking for a $25 gift card