Hi,
/30 usually is between ISP router and your edge L3 device (firewall or router), ISP should provide you another subnet to be use in your network i.e. /29 or depends on how many you request.
However, if ISP is ony assigning you a single subnet /30 which is use between their router and your edge L3 device, it's either you didn't request for additional subnet or this is the only available subnet for the service you requested (or a lousy ISP :) )
Configuring NAT with only /30 in your edge router.
- Between your router and ASA is /30 (i.e. 192.168.1.0/30)
- Inside your ASA is /24 (i.e. 192.168.2.0/24)
- From your router, route 192.168.2.0/24 to ASA
- No NAT needed in ASA
- NAT should be done in the router in which 192.168.2.0/24 is the inside ip address
Regards,
Dandy