5-3
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 NAT Examples and Reference
Examples for Network Object NAT
Figure 5-2
Dynamic NAT for Inside, Static NAT for Outside Web Server
Procedure
Step 1
Create a network object for the dynamic NAT pool to which you want to translate the inside addresses.
hostname(config)#
object network myNatPool
hostname(config-network-object)#
range 209.165.201.20 209.165.201.30
Step 2
Create a network object for the inside network.
hostname(config)#
object network myInsNet
hostname(config-network-object)#
subnet 10.1.2.0 255.255.255.0
Step 3
Enable dynamic NAT for the inside network using the dynamic NAT pool object.
hostname(config-network-object)#
nat (inside,outside) dynamic myNatPool
Step 4
Create a network object for the outside web server.
hostname(config)#
object network myWebServ
hostname(config-network-object)#
host 209.165.201.12
Step 5
Configure static NAT for the web server.
hostname(config-network-object)#
nat (outside,inside) static 10.1.2.20
Outside
Inside
10.1.2.1
209.165.201.1
Security
Appliance
myInsNet
10.1.2.0/24
We
b
Server
209.165.201.12
209.165.201.12
10.1.2.20
248773
Undo Translation
10.1.2.10
209.165.201.20
Translation
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......