cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
473
Views
0
Helpful
2
Replies

ASA5505 NAT/Translation

bardellom
Level 1
Level 1

As a packet travels through the firewall (inside => outside) is it possible to NAT the source IP (with the outside interface of the FW) and translate the destination IP? Also, the destination IP (translated IP) would need a static route in the firewall to be reachable.

Thanks

2 Replies 2

Jon Marshall
Hall of Fame
Hall of Fame

Michael

Source 192.168.5.1

destination 212.17.12.1

you want to present the destination as 10.5.1.1 to your inside client of 192.168.5.1

nat (inside) 1 192.168.5.1 255.255.255.255

global (outside) 1 interface

the above NAT's your client

static (outside,inside) 10.5.1.1 212.17.12.1 netmask 255.255.255.255

No you don't need a route to the real destination but you would need to ensure any traffic destined for 10.5.1.1 from the inside ended up at inside interface of your firewall.

Jon

Thanks Jon I will give this a try.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card