5-27
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 NAT Examples and Reference
DNS and NAT
Step 4
Create a network object for the inside IPv6 network, and configure dynamic NAT with a PAT pool.
hostname(config)#
object network IPv6_INSIDE
hostname(config-network-object)#
subnet 2001:DB8::/96
hostname(config-network-object)#
nat (inside,outside) dynamic pat-pool IPv4_POOL
PTR Modification, DNS Server on Host Network
The following figure shows an FTP server and DNS server on the outside. The ASA has a static
translation for the outside server. In this case, when an inside user performs a reverse DNS lookup for
10.1.2.56, the ASA modifies the reverse DNS query with the real address, and the DNS server responds
with the server name, ftp.cisco.com.
Figure 5-22
PTR Modification, DNS Server on Host Network
ftp.ci
s
co.com
209.165.201.10
DN
S
S
erver
O
u
t
s
ide
In
s
ide
U
s
er
10.1.2.27
S
t
a
tic Tr
a
n
s
l
a
tion on In
s
ide to:
10.1.2.56
1
2
4
3
Rever
s
e DN
S
Q
u
ery
209.165.201.10
Rever
s
e DN
S
Q
u
ery Modific
a
tion
209.165.201.10
10.1.2.56
PTR Record
ftp.cisco.com
A
S
A
Rever
s
e DN
S
Q
u
ery
10.1.2.56?
3
04002
Summary of Contents for ASA 5512-X
Page 5: ...P A R T 1 Service Policies and Access Control ...
Page 6: ......
Page 51: ...P A R T 2 Network Address Translation ...
Page 52: ......
Page 127: ...P A R T 3 Application Inspection ...
Page 128: ......
Page 255: ...P A R T 4 Connection Settings and Quality of Service ...
Page 256: ......
Page 303: ...P A R T 5 Advanced Network Protection ...
Page 304: ......
Page 339: ...P A R T 6 ASA Modules ...
Page 340: ......