
16-7
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 16 Configuring NAT
NAT Overview
Figure 16-6
Remote Host Attempts to Connect to the Real Address
Figure 16-7
shows a remote host attempting to initiate a connection to a mapped address. This address
is not currently in the translation table, so the FWSM drops the packet.
Figure 16-7
Remote Host Attempts to Initiate a Connection to a Mapped Address
Note
For the duration of the translation, a remote host can initiate a connection to the translated host if an
access list allows it. Because the address is unpredictable, a connection to the host is unlikely. However
in this case, you can rely on the security of the access list.
Web Server
www.example.com
Outside
Inside
209.165.201.2
10.1.2.1
10.1.2.27
Translation
209.165.201.10
10.1.2.27
10.1.2.27
132950
FWSM
Web Server
www.example.com
Outside
Inside
209.165.201.2
10.1.2.1
10.1.2.27
209.165.201.10
132951
FWSM
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......