Firewall
Configuring the NAT Rules to Securely Access a Remote Network
Cisco ISA500 Series Integrated Security Appliance Administrator Guide
192
6
Configuring the NAT Rules to Securely Access a Remote
Network
Network address translation (NAT) enables private IP networks to connect to the
Internet. NAT replaces a private IP address with a public IP address, translating the
private addresses in the internal private network into legal, routable addresses
that can be used on the public Internet. In this way, NAT conserves public
addresses because it can be configured to advertise only one public address for
the entire network to the outside world.
NAT can also provide the following benefits:
•
Security:
Keeping internal IP addresses hidden discourages direct attacks.
•
IP routing solutions:
Overlapping IP addresses are not a problem when
you use NAT.
•
Flexibility:
You can change internal IP addressing schemes without
affecting the public addresses available externally; for example, for a server
accessible to the Internet, you can maintain a fixed IP address for Internet
use, but internally, you can change the server address.
This section includes the following topics:
•
Configuring Dynamic PAT Rules, page 193
•
Configuring Static NAT Rules, page 194
•
Configuring Port Forwarding Rules, page 195
•
Configuring Port Triggering Rules, page 196
•
Configuring Advanced NAT Rules, page 197
•
Viewing NAT Translation Status, page 199
Services
SMTP
Source Address
Any
Destination Address
OffsiteMail
Match Action
Deny
Parameter
Value