cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
253
Views
0
Helpful
2
Replies

using NAT with a difference IP/range from the outside interface + proxy ARP

SJ K
Level 5
Level 5

Hi all gurus,

I need to NAT the source address of the traffic from my local LAN going out of the ASA firewall.

From the diagram above, my outside interface IP on the ASA firewall is set at 192.168.12.2

q1) Am i able to set NAT on this outside interface to use another range of IP (e.g. 10.10.10.1)  as its source when routing traffic from the local LAN to Router 0 (10.10.10.2) ?

q2) if the above is achievable,  how does Router 0 know how to send to the ASA firewall ?
Does it means that the ASA firewall will reply to ARP request for 10.10.10.1 even though its physical interface is set to 192.168.12.2 ?
Does it also means that I have to turn on PROXY-ARP on the ASA firewall outside interface in order for the setup to work ?

Regards,
Noob

2 Replies 2

SJ K
Level 5
Level 5

Anybody ?

rasmus.elmholt
Level 7
Level 7

Hi

This wont work. Router0 and the ASA is not on the same subnet. For the ASA to NAT on an address the address needs to be on the same subnet as the WAN, or the address needs to be routed to the ASA.

Review Cisco Networking for a $25 gift card