cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
356
Views
5
Helpful
3
Replies

Static IP NAT

mengxi zhang
Level 1
Level 1

Hi Engieer,

I have two ASA 5500 devices,and setup a VPN tunnel between J(192.168.0.x) to K(192.168.1.x) sucessfully.

I can make a static NAT just like a pravite IP to a public IP at J site. As following:

static (inside,outside) tcp A.B.C.D 1433 192.168.0.10 1433 netmask 255.255.255.255

Qustion:

Can I make a static NAT at J site through VPN tunnel?Can I access it from outside?

As following:

static (inside,outside) tcp A.B.C.D 1433 192.168.1.10 1433 netmask 255.255.255.255

Please, thanks in advance!

3 Replies 3

Dennis Mink
VIP Alumni
VIP Alumni

That is not gonna work, you are doing a static NAT with private IP address 192.168.1.10 on a public P address that is on an ASA that has no IP address in the 192.168.1.0 range, so even though you might be able to statically NAT that, the packet will never get routed back to that ASA from K.

I hope that makes sense.

Please rate if useful.

Please remember to rate useful posts, by clicking on the stars below.

Hi Dennis,

Thanks for your reply. Can I add many route rule to forword outside trafic to the server in site K? Is it possible ?

nurbol555
Level 1
Level 1

Hi

It doesn't matter what you are doing, changing a static NAT with private IP address on a public P address or private ip address on a private ip address, it will work, NAT - it's not changing private IP address on a public P address, it's changing one ip address to other ip address, doesn't matter what kind of ip address is it

Hope its helpfull

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: