cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
994
Views
0
Helpful
2
Replies

Source NAT Pool

BlueyVIII
Level 1
Level 1

We have a system in our DMZ which regularly hangs and the supplier have told us it's because we're NAT'ing the source address into the DMZ and the server can't handle so many connections coming from a single source address. Their recommendation is to present each clients 'real' IP Address to the server but for many reasons we can't do this.

 

Is there a way to configure a CISCO ASA (FPR 2110) to NAT the Source Address into the DMZ but using a pool of IP Addresses, rather than a single address?? I'm hoping we can spread the connections to the server across many different source IP Addresses..

 

Any help gratefully received....

2 Replies 2

balaji.bandi
Hall of Fame
Hall of Fame

yes you can do with Multiple NAT Address pool, rather rely on single 1IP address have Limitation of multiplexing.

 

you can also fine tune with timings, depends on your config, what is configured, what time outs ? we need more information and config to suggest better here.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

 

   You configure regular dynamic NAT, and you make use of the "round-robin" functionality, otherwise all translations will still use the first IP from the pool till all ports are depleted.

 

Regards,

Cristian Matei.

Review Cisco Networking for a $25 gift card