5-18
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 NAT Examples and Reference
NAT for VPN
Figure 5-15
Interface PAT and Identity NAT for Site-to-Site VPN
The following figure shows a VPN client connected to ASA1 (Boulder), with a Telnet request for a server
(10.2.2.78) accessible over a site-to-site tunnel between ASA1 and ASA2 (San Jose). Because this is a
hairpin connection, you need to enable intra-interface communication, which is also required for
non-split-tunneled Internet-bound traffic from the VPN client. You also need to configure identity NAT
between the VPN client and the Boulder & San Jose networks, just as you would between any networks
connected by VPN to exempt this traffic from outbound NAT rules.
Figure 5-16
VPN Client Access to Site-to-Site VPN
See the following sample NAT configuration for ASA1 (Boulder):
! Enable hairpin for VPN client traffic:
same-security-traffic permit intra-interface
! Identify local VPN network, & perform object interface PAT when going to Internet:
10.1.1.6
ASA1
ASA2
10.2.2.78
Internet
Src: 10.1.1.6
10.1.1.6
203.0.113.1:6070
Src: 10.1.1.6
10.1.1.6
D
s
t: 10.2.2.7
8
10.2.2.7
8
San Jose
Inside
Boulder
Inside
1.
IM to 10.2.2.78
Src: 10.1.1.6
A.
HTTP to
www.example.com
Src: 10.1.1.6
3.
IM received
C.
HTTP request to www.example.com
2.
Identity NAT
b
etween NWs connected
b
y VPN
B.
ASA performs interface PAT for
outgoing traffic.
Src: 203.0.113.1:6070
www.example.com
ASA Outside IP: 203.0.113.1
303459
Site-to-Site VPN Tunnel
VPN Client
209.165.201.10
10.1.1.6
ASA1
ASA2
10.2.2.78
Internet
San Jose
Inside
Boulder
Inside
Site-to-Site VPN Tunnel
4.
HTTP request received
1.
HTTP request to 10.2.2.78
10.3.3.10
209.165.201.10
2.
ASA decrypts packet; src address is
now local address
Src: 10.3.3.10
10.3.3.10
D
s
t: 10.2.2.7
8
10.2.2.7
8
3.
Identity NAT
b
etween VPN Client &
San Jose NWs; intra-interface config req’d
Src: 209.165.201.10
Src: 10.3.3.10
303460
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...