5-14
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 NAT Examples and Reference
Routing NAT Packets
Figure 5-11
Proxy ARP and Virtual Telnet
Transparent Mode Routing Requirements for Remote Networks
When you use NAT in transparent mode, some types of traffic require static routes. See the general
operations configuration guide for more information.
Determining the Egress Interface
When the ASA receives traffic for a mapped address, the ASA untranslates the destination address
according to the NAT rule, and then it sends the packet on to the real address. The ASA determines the
egress interface for the packet in the following ways:
•
Transparent mode—The ASA determines the egress interface for the real address by using the NAT
rule; you must specify the source and destination interfaces as part of the NAT rule.
•
Routed mode—The ASA determines the egress interface in one of the following ways:
–
You configure the interface in the NAT rule—The ASA uses the NAT rule to determine the
egress interface. However, you have the option to always use a route lookup instead. In certain
scenarios, a route lookup override is required; for example, see
–
You do not configure the interface in the NAT rule—The ASA uses a route lookup to determine
the egress interface.
The following figure shows the egress interface selection method in routed mode. In almost all cases, a
route lookup is equivalent to the NAT rule interface, but in some configurations, the two methods might
differ.
209.165.201.11
Virt
ua
l Telnet:
209.165.200.2
3
0
Identity NAT for
209.165.200.2
3
0
between in
s
ide
a
nd o
u
t
s
ide
with Proxy ARP
O
u
t
s
ide
In
s
ide
S
erver
1
2
3
Telnet to 209.165.200.2
3
0.
Comm
u
nic
a
te with
s
erver.
A
u
thentic
a
te.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...