data:image/s3,"s3://crabby-images/c1215/c1215a412d8afa5dd75436f5d348d6c0907171bb" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 306"
16-2
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 16 Configuring NAT
NAT Overview
Introduction to NAT
Address translation substitutes the real address in a packet with a mapped address that is routable on the
destination network. NAT is comprised of two steps: the process in which a real address is translated into
a mapped address, and then the process to undo translation for returning traffic. NAT is supported in both
routed and transparent firewall mode.
The FWSM translates an address when a NAT rule matches the traffic. If no NAT rule matches,
processing for the packet continues. The exception is when you enable NAT control. NAT control
requires that packets traversing from a higher security interface (inside) to a lower security interface
(outside) match a NAT rule, or else processing for the packet stops. (See the
“Security Level Overview”
section on page 6-1
for more information about security levels, and see the
“NAT Control” section on
page 16-5
for more information about NAT control.)
Note
In this document, all types of translation are generally referred to as NAT. When discussing NAT, the
terms
inside
and
outside
are relative, and represent the security relationship between any two interfaces.
The higher security level is inside and the lower security level is outside; for example, interface 1 is at
60 and interface 2 is at 50, so interface 1 is “inside” and interface 2 is “outside.”
Some of the benefits of NAT are as follows:
•
You can use private addresses on your inside networks. Private addresses are not routable on the
Internet. (See the
“Private Networks” section on page E-2
for more information.)
•
NAT hides the real addresses from other networks, so attackers cannot learn the real address of a
host.
•
You can resolve IP routing problems such as overlapping addresses.
Note
See
Table 22-1 on page 22-4
for information about protocols that do not support NAT.
NAT in Routed Mode
Figure 16-1
shows a typical NAT scenario in routed mode, with a private network on the inside. When
the inside host at 10.1.1.27 sends a packet to a web server, the real source address, 10.1.1.27, of the
packet is changed to a mapped address, 209.165.201.10. When the server responds, it sends the response
to the mapped address, 209.165.201.10, and the FWSM receives the packet. The FWSM then undoes the
translation of the mapped address, 209.165.201.10 back to the real address, 10.1.1.1.27 before sending
it on to the host.
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......