17-18
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 17 Configuring NAT
Using Dynamic NAT and PAT
You can enter a
nat
command for each interface using the same NAT ID; they all use the same
global
command when traffic exits a given interface. For example, you can configure
nat
commands for Inside
and DMZ interfaces, both on NAT ID 1. Then you configure a
global
command on the Outside interface
that is also on ID 1. Traffic from the Inside interface and the DMZ interface share a mapped pool or a
PAT address when exiting the Outside interface (see
Figure 17-15
).
Figure 17-15
nat Commands on Multiple Interfaces
See the following commands for this example:
hostname(config)#
nat (inside) 1 10.1.2.0 255.255.255.0
hostname(config)#
nat (dmz) 1 10.1.1.0 255.255.255.0
hostname(config)#
global (outside) 1 209.165.201.3-209.165.201.10
Web Server:
www.cisco.com
Outside
DMZ
Inside
Global 1: 209.165.201.3-
209.165.201.10
NAT 1: 10.1.2.0/24
NAT 1: 10.1.1.0/24
10.1.1.15
10.1.2.27
130028
Translation
209.165.201.3
10.1.2.27
Translation
209.165.201.4
10.1.1.15
Summary of Contents for 500 Series
Page 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Page 45: ...P A R T 1 Getting Started and General Information ...
Page 46: ......
Page 277: ...P A R T 2 Configuring the Firewall ...
Page 278: ......
Page 561: ...P A R T 3 Configuring VPN ...
Page 562: ......
Page 891: ...P A R T 4 System Administration ...
Page 892: ......
Page 975: ...P A R T 5 Reference ...
Page 976: ......