02-04-2009 09:34 AM - edited 03-11-2019 07:45 AM
Hi ,
I have a question about ASA which i happen to come across
Is it not possible to NAT with logical IP addresses or IP addresses for which physical interfaces are not configred on the ASA.If not then how can i NAT for multiple IP pools of my ISP for which physical interface does not exist on my firewall
Solved! Go to Solution.
02-04-2009 09:52 AM
As long as you upstream router(s) route
down these IP pools to the ASA, this will
work just fine.
Let say your "outside" interface is
1.1.1.1/24 but you want to static NAT
129.174.1.0/24 to 192.168.1.0/24 on the ASA:
on the upstream router:
ip route 129.174.1.0 255.255.255.0 1.1.1.1
on the ASA:
static (i,o) 129.174.1.0 192.168.1.0 /24
Easy right?
02-04-2009 09:52 AM
As long as you upstream router(s) route
down these IP pools to the ASA, this will
work just fine.
Let say your "outside" interface is
1.1.1.1/24 but you want to static NAT
129.174.1.0/24 to 192.168.1.0/24 on the ASA:
on the upstream router:
ip route 129.174.1.0 255.255.255.0 1.1.1.1
on the ASA:
static (i,o) 129.174.1.0 192.168.1.0 /24
Easy right?
02-07-2009 08:11 PM
thanx that was very useful information
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide