4-5
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 4 Network Address Translation (NAT
NAT Basics
NAT Rule Order
Network object NAT rules and twice NAT rules are stored in a single table that is divided into three
sections. Section 1 rules are applied first, then section 2, and finally section 3, until a match is found.
For example, if a match is found in section 1, sections 2 and 3 are not evaluated. The following table
shows the order of rules within each section.
For section 2 rules, for example, you have the following IP addresses defined within network objects:
192.168.1.0/24 (static)
Table 4-1
NAT Rule Table
Table Section
Rule Type
Order of Rules within the Section
Section 1
Twice NAT
Applied on a first match basis, in the order they appear in the
configuration. Because the first match is applied, you must
ensure that specific rules come before more general rules, or
the specific rules might not be applied as desired. By default,
twice NAT rules are added to section 1.
Note
If you configure EasyVPN remote, the ASA
dynamically adds invisible NAT rules to the end of this
section. Be sure that you do not configure a twice NAT
rule in this section that might match your VPN traffic,
instead of matching the invisible rule. If VPN does not
work due to NAT failure, consider adding twice NAT
rules to section 3 instead.
Section 2
Network object NAT
If a match in section 1 is not found, section 2 rules are applied
in the following order, as automatically determined by the
ASA:
1.
Static rules.
2.
Dynamic rules.
Within each rule type, the following ordering guidelines are
used:
1.
Quantity of real IP addresses—From smallest to largest.
For example, an object with one address will be assessed
before an object with 10 addresses.
2.
For quantities that are the same, then the IP address number
is used, from lowest to highest. For example, 10.1.1.0 is
assessed before 11.1.1.0.
3.
If the same IP address is used, then the name of the network
object is used, in alphabetical order. For example,
abracadabra is assessed before catwoman.
Section 3
Twice NAT
If a match is still not found, section 3 rules are applied on a first
match basis, in the order they appear in the configuration. This
section should contain your most general rules. You must also
ensure that any specific rules in this section come before
general rules that would otherwise apply. You can specify
whether to add a twice NAT rule to section 3 when you add the
rule.
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...