09-21-2016 04:38 AM - edited 03-05-2019 07:06 AM
09-21-2016 04:53 AM
You need not configure second 'outside' interface. Firewall should have one outside interface with one subnet and do the NAT for second third and so on without configuring IP subnet on interface just make sure that ouside world know that second,third and so on range on your Firewall I mean routing.
09-21-2016 05:18 AM
Hi, Thank you for your quick response. how do I set up NAT for the second/third ranges using ASDM?
Thank in advance
09-21-2016 11:57 AM
How did you set up NAT for the first range? I am guessing that perhaps you created objects for the addresses in the range and then configured NAT with the object of the inside address and of the public address. Or perhaps you just configured NAT for the object of the inside address to the public address. You would do essentially the same for the second or third range.
HTH
Rick
09-22-2016 02:46 AM
Hi,
The 'outside interface was allocated an IP in the public range 1.1.1.40, all other addresses were allocated to internal devices using ASDM and creating a public facing server. This created a public to internal NAT rule.
I am not sure how to add 3.3.3.x and 6.6.6.x to the outside interface, allowing me to allocate additional public addresses to internal servers.
Thanks in advance
09-22-2016 05:53 AM
The thing is that you do not need to add those addresses to any interface. All you need to do is to create the NAT rules.
HTH
Rick
09-22-2016 10:55 PM
Thank you, how would i create the rules in the ASDM manager? Is it literally in the NAT section and select the I/F and IP ranges?
Thanks
09-23-2016 06:44 AM
Yes it is literally in the NAT section (with appropriate entries in the object section).
HTH
Rick
09-27-2016 07:38 AM
09-27-2016 07:43 AM
I believe that you want the middle option which add an object nat rule.
HTH
Rick
09-27-2016 08:09 AM
I will give it a try. Thanks
09-28-2016 06:06 AM
09-28-2016 07:04 AM
The translated address would be taken from the set of addresses that the ISP gives you. If you do not have these addresses yet then it is too early to be configuring this address translation.
I am not sure that it makes any difference whether the translated addresses are in the same subnet or not.
HTH
Rick
09-22-2016 02:07 PM
Is the new IP block from the same ISP? If it is, are they routing this new /28 to your current interface?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide