In and Out NAT question

Unanswered Question
Jun 5th, 2007

Hi All,

I have a scenario i am trying to configure.

I have 2 internal hosts behind 2 different internal interfaces with private ip networks. (Network A and Network B).

I also have 2 public IP's i am using to hide NAT traffic going to the internet.

(IP 1 for Network A and IP 2 For Network B).

The Problem:

I have one internet host that needs to access an internal IP in Network B using the public IP 1.

I am using ASDM to configure it all, using Dynamic NAT for the outgoing traffic and Static Policy NAT for the incoming traffic, but i guess this is wrong because it simply doesn't work.

I also tried using static policy NAT for both incoming and outgoing traffic without success.

Can someone tell me if there is a solution and what is it?



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
emad.silicon Tue, 06/05/2007 - 03:15

ok friend if i understand your problem so the solution will be :

global(outside) 1 ip-public 1

global(outside) 2 ip-public 2

nat(inside1) 1 network a

nat(inside2) 2 network b

static(inside2,outside) public3 Pri-ip-Net2

access-list any-name permit any public3

access-group any-name in int outside

you must use a 3th public ip to assigne it for the internal host by useing static command

pleas if this don't solue your problem can you send me the info in more detiled


zivmosery Tue, 06/05/2007 - 03:52

First of all thanks for you answer.

So in other words what you are saying is that i can't use 1 IP address for both incoming and outgoing connections?

emad.silicon Wed, 06/06/2007 - 02:33

Hi friend :

No you can use 1 ip for in and out but you have to write the comand in more detiled e.g

static(inside,outside)tcp ip1 port1 ip2 port2

but in your case you don't expline that

bec if you don't spesfied a port so you will use this public to this privaite in all connections.

i wish you understand what i talk about .


JACKY NIGLIO Mon, 06/11/2007 - 14:34


i have a same problem with ASA 5505

I have just one Ip public and it's doesn't work with

static ( inside,outside )tcp interface www wwww

but with a pix 501 that work fine but not with ASA ?

Do you have a solution ?


This Discussion