cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3806
Views
1
Helpful
3
Replies

NAT rule vs network object NAt in the ASA ?!!

Dr.X
Level 2
Level 2

hi all ,

im asking here whats the differnce between the NAT rule  and network object "NAT" ???

i found that i can do my nat rules by two methods

by

NAT rule  & object "NAT"

but im asking here whats the differnce between them ??

1 Accepted Solution

Accepted Solutions

prajithtr_2
Level 1
Level 1

Object NAT is nothing but its a new feature introduced in ASA version 8.3&Later to configure NAT rules(Static,Dynamic and PAT)

All NAT rules that are configured as a parameter of a network object are considered to be network object NAT rules. Network object NAT is a quick and easy way to configure NAT for a network object, which can be a single IP address, a range of addresses, or a subnet. After you configure the network object, you can then identify the mapped address for that object.

Refer :

http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/nat_objects.html

***Please rate if it is usefull***

View solution in original post

3 Replies 3

prajithtr_2
Level 1
Level 1

Object NAT is nothing but its a new feature introduced in ASA version 8.3&Later to configure NAT rules(Static,Dynamic and PAT)

All NAT rules that are configured as a parameter of a network object are considered to be network object NAT rules. Network object NAT is a quick and easy way to configure NAT for a network object, which can be a single IP address, a range of addresses, or a subnet. After you configure the network object, you can then identify the mapped address for that object.

Refer :

http://www.cisco.com/c/en/us/td/docs/security/asa/asa83/asdm63/configuration_guide/config/nat_objects.html

***Please rate if it is usefull***

thankx

Yes its a different way to do nat, but there are differences, rule base nat you can change the order of your rules, object based nat you cant, also nat rules are performed in order, so rule 1, 2, 3 etc. I'm pretty sure object based rules come after all of your "nat rules" so if you configure a nat rule and and an object rule, the nat rule takes precedence i believe, but I might have that reversed. either way one of them takes precedence because it is in the rule base first, you can also change the order of those.

Review Cisco Networking for a $25 gift card