17-23
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 17 Configuring NAT
Using Dynamic NAT and PAT
Configuring Dynamic NAT or PAT
This section describes how to configure dynamic NAT or dynamic PAT. The configuration for dynamic
NAT and PAT are almost identical; for NAT you specify a range of mapped addresses, and for PAT you
specify a single address.
Figure 17-20
shows a typical dynamic NAT scenario. Only translated hosts can create a NAT session,
and responding traffic is allowed back. The mapped address is dynamically assigned from a pool defined
by the
global
command.
Figure 17-20
Dynamic NAT
Figure 17-21
shows a typical dynamic PAT scenario. Only translated hosts can create a NAT session, and
responding traffic is allowed back. The mapped address defined by the
global
command is the same for
each translation, but the port is dynamically assigned.
Figure 17-21
Dynamic PAT
For more information about dynamic NAT, see the
“Dynamic NAT” section on page 17-6
. For more
information about PAT, see the
“PAT” section on page 17-8
.
Note
If you change the NAT configuration, and you do not want to wait for existing translations to time out
before the new NAT information is used, you can clear the translation table using the
clear xlate
command. However, clearing the translation table disconnects all current connections that use
translations.
To configure dynamic NAT or PAT, perform the following steps:
Step 1
To identify the real addresses that you want to translate, enter one of the following commands:
10.1.1.1
209.165.201.1
Inside
Outside
10.1.1.2
209.165.201.2
130032
Security
Appliance
10.1.1.1:1025
209.165.201.1:2020
Inside
Outside
10.1.1.1:1026
209.165.201.1:2021
10.1.1.2:1025
209.165.201.1:2022
130034
Security
Appliance
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......