![Cisco ASA 5512-X Скачать руководство пользователя страница 63](http://html.mh-extra.com/html/cisco/asa-5512-x/asa-5512-x_configuration-manual_63717063.webp)
4-11
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 4 Network Address Translation (NAT
Guidelines for NAT
•
Source Identity NAT
–
The real and mapped objects must match. You can use the same object for both, or you can
create separate objects that contain the same IP addresses.
•
Destination Static NAT or Static NAT with port translation (the destination translation is always
static):
–
Although the main feature of twice NAT is the inclusion of the destination IP address, the
destination address is optional. If you do specify the destination address, you can configure
static translation for that address or just use identity NAT for it. You might want to configure
twice NAT without a destination address to take advantage of some of the other qualities of
twice NAT, including the use of network object groups for real addresses, or manually ordering
of rules. For more information, see
Comparing Network Object NAT and Twice NAT, page 4-4
–
For identity NAT, the real and mapped objects must match. You can use the same object for both,
or you can create separate objects that contain the same IP addresses.
–
The static mapping is typically one-to-one, so the real addresses have the same quantity as the
mapped addresses. You can, however, have different quantities if desired.
–
For static interface NAT with port translation (routed mode only), you can specify the
interface
keyword instead of a network object/group for the mapped address.
Twice NAT Guidelines for Service Objects for Real and Mapped Ports
You can optionally configure service objects for:
•
Source real port (Static only)
or
Destination real port
•
Source mapped port (Static only)
or
Destination mapped port
Use the
object service
command to create the objects.
Consider the following guidelines when creating objects for twice NAT.
•
NAT only supports TCP or UDP. When translating a port, be sure the protocols in the real and
mapped service objects are identical (both TCP or both UDP).
•
The “not equal” (
neq
) operator is not supported.
•
For identity port translation, you can use the same service object for both the real and mapped ports.
•
Source Dynamic NAT—Source Dynamic NAT does not support port translation.
•
Source Dynamic PAT (Hide)—Source Dynamic PAT does not support port translation.
•
Source Static NAT, Static NAT with port translation, or Identity NAT—A service object can contain
both a source and destination port; however, you should specify
either
the source
or
the destination
port for both service objects. You should only specify
both
the source and destination ports if your
application uses a fixed source port (such as some DNS servers); but fixed source ports are rare. For
example, if you want to translate the port for the source host, then configure the source service.
•
Destination Static NAT or Static NAT with port translation (the destination translation is always
static)—For non-static source NAT, you can only perform port translation on the destination. A
service object can contain both a source and destination port, but only the destination port is used
in this case. If you specify the source port, it will be ignored.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...