9-5
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 9 Network Address Translation (NAT)
NAT Basics
NAT Rule Order
Network object NAT rules and twice NAT rules are stored in a single table that is divided into three
sections. Section 1 rules are applied first, then section 2, and finally section 3, until a match is found.
For example, if a match is found in section 1, sections 2 and 3 are not evaluated. The following table
shows the order of rules within each section.
For section 2 rules, for example, you have the following IP addresses defined within network objects:
192.168.1.0/24 (static)
Table 9-1
NAT Rule Table
Table Section
Rule Type
Order of Rules within the Section
Section 1
Twice NAT
Applied on a first match basis, in the order they appear in the
configuration. Because the first match is applied, you must
ensure that specific rules come before more general rules, or
the specific rules might not be applied as desired. By default,
twice NAT rules are added to section 1.
Note
If you configure EasyVPN remote, the ASA
dynamically adds invisible NAT rules to the end of this
section. Be sure that you do not configure a twice NAT
rule in this section that might match your VPN traffic,
instead of matching the invisible rule. If VPN does not
work due to NAT failure, consider adding twice NAT
rules to section 3 instead.
Section 2
Network object NAT
If a match in section 1 is not found, section 2 rules are applied
in the following order, as automatically determined by the
ASA:
1.
Static rules.
2.
Dynamic rules.
Within each rule type, the following ordering guidelines are
used:
1.
Quantity of real IP addresses—From smallest to largest.
For example, an object with one address will be assessed
before an object with 10 addresses.
2.
For quantities that are the same, then the IP address number
is used, from lowest to highest. For example, 10.1.1.0 is
assessed before 11.1.1.0.
3.
If the same IP address is used, then the name of the network
object is used, in alphabetical order. For example,
abracadabra is assessed before catwoman.
Section 3
Twice NAT
If a match is still not found, section 3 rules are applied on a first
match basis, in the order they appear in the configuration. This
section should contain your most general rules. You must also
ensure that any specific rules in this section come before
general rules that would otherwise apply. You can specify
whether to add a twice NAT rule to section 3 when you add the
rule.
Summary of Contents for ASA 5508-X
Page 11: ...P A R T 1 Access Control ...
Page 12: ......
Page 157: ...P A R T 2 Network Address Translation ...
Page 158: ......
Page 233: ...P A R T 3 Service Policies and Application Inspection ...
Page 234: ......
Page 379: ...P A R T 4 Connection Management and Threat Detection ...
Page 380: ......