10-11
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 10 NAT Examples and Reference
Routing NAT Packets
Figure 10-9
NAT Example: Transparent Mode
1.
When the inside host at 10.1.1.75 sends a packet to a web server, the real source address of the
packet, 10.1.1.75, is changed to a mapped address, 209.165.201.15.
2.
When the server responds, it sends the response to the mapped address, 209.165.201.15, and the
ASA receives the packet because the upstream router includes this mapped network in a static route
directed to the ASA management IP address. See
Mapped Addresses and Routing, page 10-12
for
more information about required routes.
3.
The ASA then undoes the translation of the mapped address, 209.165.201.15, back to the real
address, 10.1.1.1.75. Because the real address is directly-connected, the ASA sends it directly to the
host.
4.
For host 192.168.1.2, the same process occurs, except for returning traffic, the ASA looks up the
route in its routing table and sends the packet to the downstream router at 10.1.1.3 based on the ASA
static route for 192.168.1.0/24. See
Transparent Mode Routing Requirements for Remote Networks,
for more information about required routes.
Routing NAT Packets
The ASA needs to be the destination for any packets sent to the mapped address. The ASA also needs to
determine the egress interface for any packets it receives destined for mapped addresses. This section
describes how the ASA handles accepting and delivering packets with NAT.
•
Mapped Addresses and Routing, page 10-12
M
a
n
a
gement IP
10.1.1.1
www.ex
a
mple.com
10.1.1.2
Internet
S
o
u
rce Addr Tr
a
n
s
l
a
tion
209.165.201.10
192.168.1.2
S
o
u
rce Addr Tr
a
n
s
l
a
tion
209.165.201.15
10.1.1.75
A
S
A
10.1.1.75
10.1.1.3
192.16
8
.1.1
192.16
8
.1.2
Network 2
S
t
a
tic ro
u
te on ro
u
ter:
209.165.201.0/27 to 10.1.1.1
S
t
a
tic ro
u
te on A
S
A:
192.16
8
.1.0/24 to 10.1.1.3
250261
Содержание ASA 5508-X
Страница 11: ...P A R T 1 Access Control ...
Страница 12: ......
Страница 60: ...4 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 4 Access Rules History for Access Rules ...
Страница 157: ...P A R T 2 Network Address Translation ...
Страница 158: ......
Страница 204: ...9 46 Cisco ASA Series Firewall CLI Configuration Guide Chapter 9 Network Address Translation NAT History for NAT ...
Страница 232: ...10 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 10 NAT Examples and Reference DNS and NAT ...
Страница 233: ...P A R T 3 Service Policies and Application Inspection ...
Страница 234: ......
Страница 379: ...P A R T 4 Connection Management and Threat Detection ...
Страница 380: ......
Страница 400: ...16 20 Cisco ASA Series Firewall CLI Configuration Guide Chapter 16 Connection Settings History for Connection Settings ...
Страница 414: ...17 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 Quality of Service History for QoS ...