4-13
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 4 Network Address Translation (NAT
Dynamic NAT
The following figure shows a remote host attempting to initiate a connection to a mapped address. This
address is not currently in the translation table; therefore, the ASA drops the packet.
Figure 4-3
Remote Host Attempts to Initiate a Connection to a Mapped Address
Dynamic NAT Disadvantages and Advantages
Dynamic NAT has these disadvantages:
•
If the mapped pool has fewer addresses than the real group, you could run out of addresses if the
amount of traffic is more than expected.
Use PAT or a PAT fall-back method if this event occurs often because PAT provides over 64,000
translations using ports of a single address.
•
You have to use a large number of routable addresses in the mapped pool, and routable addresses
may not be available in large quantities.
The advantage of dynamic NAT is that some protocols cannot use PAT. PAT does not work with the
following:
•
IP protocols that do not have a port to overload, such as GRE version 0.
•
Some multimedia applications that have a data stream on one port, the control path on another port,
and are not open standard.
See
Default Inspections and NAT Limitations, page 6-6
for more information about NAT and PAT
support.
Web
S
erver
www.ex
a
mple.com
O
u
t
s
ide
In
s
ide
209.165.201.2
10.1.2.1
10.1.2.27
S
ec
u
rity
Appli
a
nce
209.165.201.10
1
3
2217
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......