
5-9
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 NAT Examples and Reference
NAT in Routed and Transparent Mode
Step 7
Add a service object for HTTP:
hostname(config)#
object service HTTPObj
hostname(config-network-object)#
service
tcp
destination eq http
Step 8
Configure the second twice NAT rule:
hostname(config)#
nat (inside,outside) source dynamic myInsideNetwork PATaddress2
destination static TelnetWebServer TelnetWebServer service HTTPObj HTTPObj
Example: Twice NAT with Destination Address Translation
The following figure shows a remote host connecting to a mapped host. The mapped host has a twice
static NAT translation that translates the real address only for traffic to and from the 209.165.201.0/27
network. A translation does not exist for the 209.165.200.224/27 network, so the translated host cannot
connect to that network, nor can a host on that network connect to the translated host.
Figure 5-7
Twice Static NAT with Destination Address Translation
NAT in Routed and Transparent Mode
You can configure NAT in both routed and transparent firewall mode. This section describes typical
usage for each firewall mode.
•
•
NAT in Transparent Mode, page 5-10
209.165.201.11
209.165.200.225
DMZ
In
s
ide
No Tr
a
n
s
l
a
tion
10.1.2.27
10.1.2.27
10.1.2.0/27
209.165.201.0/27
209.165.200.224/27
Undo Tr
a
n
s
l
a
tion
209.165.202.128
1
3
00
3
7
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......