10-3
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 10 NAT Examples and Reference
Examples for Network Object NAT
Figure 10-2
Dynamic NAT for Inside, Static NAT for Outside Web Server
Procedure
Step 1
Create a network object for the dynamic NAT pool to which you want to translate the inside addresses.
hostname(config)#
object network myNatPool
hostname(config-network-object)#
range 209.165.201.20 209.165.201.30
Step 2
Create a network object for the inside network.
hostname(config)#
object network myInsNet
hostname(config-network-object)#
subnet 10.1.2.0 255.255.255.0
Step 3
Enable dynamic NAT for the inside network using the dynamic NAT pool object.
hostname(config-network-object)#
nat (inside,outside) dynamic myNatPool
Step 4
Create a network object for the outside web server.
hostname(config)#
object network myWebServ
hostname(config-network-object)#
host 209.165.201.12
Step 5
Configure static NAT for the web server.
hostname(config-network-object)#
nat (outside,inside) static 10.1.2.20
Outside
Inside
10.1.2.1
209.165.201.1
Security
Appliance
myInsNet
10.1.2.0/24
Web Server
209.165.201.12
209.165.201.12
10.1.2.20
24877
3
Undo Translation
10.1.2.10
209.165.201.20
Translation
Summary of Contents for ASA 5508-X
Page 11: ...P A R T 1 Access Control ...
Page 12: ......
Page 157: ...P A R T 2 Network Address Translation ...
Page 158: ......
Page 233: ...P A R T 3 Service Policies and Application Inspection ...
Page 234: ......
Page 379: ...P A R T 4 Connection Management and Threat Detection ...
Page 380: ......