data:image/s3,"s3://crabby-images/fcb81/fcb811dac4326d8f88a09ae968975e837103202e" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 330"
16-26
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 16 Configuring NAT
Using Dynamic NAT and PAT
Configuring Dynamic NAT or PAT
This section describes how to configure dynamic NAT or dynamic PAT. The configuration for dynamic
NAT and PAT are almost identical; for NAT you specify a range of mapped addresses, and for PAT you
specify a single address.
Figure 16-20
shows a typical dynamic NAT scenario. Only translated hosts can create a NAT session,
and responding traffic is allowed back. The mapped address is dynamically assigned from a pool defined
by the
global
command.
Figure 16-20
Dynamic NAT
Figure 16-21
shows a typical dynamic PAT scenario. Only translated hosts can create a NAT session, and
responding traffic is allowed back. The mapped address defined by the
global
command is the same for
each translation, but the port is dynamically assigned.
Figure 16-21
Dynamic PAT
For more information about dynamic NAT, see the
“Dynamic NAT” section on page 16-6
. For more
information about PAT, see the
“PAT” section on page 16-8
.
Note
If you change the NAT configuration, and you do not want to wait for existing translations to time out
before the new NAT information is used, you can clear the translation table using the
clear xlate
command. However, clearing the translation table disconnects all current connections that use
translations.
To configure dynamic NAT or PAT, perform the following steps:
Step 1
To identify the real addresses that you want to translate, enter one of the following commands:
•
Policy NAT:
hostname(config)#
nat
(
real_interface
)
nat_id
access-list
acl_name
[
dns
] [
outside
]
[[
tcp
]
tcp_max_conns
[
emb_limit
]] [
udp
udp_max_conns
] [
norandomseq
]
10.1.1.1
209.165.201.1
Inside
Outside
10.1.1.2
209.165.201.2
132934
FWSM
10.1.1.1:1025
209.165.201.1:2020
Inside
Outside
10.1.1.1:1026
209.165.201.1:2021
10.1.1.2:1025
209.165.201.1:2022
132936
FWSM
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......