NAT Question - ASA 55xx

Unanswered Question

Hi All,

Just a quick question...

I have an ASA that is configured with the following...

Inside IP:


Outside IP:

*All IPs are fictious of course*

Currently my ASA is configured to NAT all inside IPs to the outside interface.  My plan is to change the outside interface to a Private IP address, as I'm looking to put a router infront of it.  Instead of NAT'ing to the outside interface, can I NAT to a free IP in my block?  If so, what would be the desired configuration?

global <?> 1 sure on the syntax.  Looking for assistance on that as well

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
danrya Mon, 10/04/2010 - 06:58
User Badges:
  • Bronze, 100 points or more

I'm guessing that your current config has:

global (outside) 1 interface

That tells it to use the interface IP address and NAT any thing that matches "nat (inside) 1".  All you need to do is change the "global" command to the ip address(es) that you want it to NAT to.

global (outside) 1

or something like this (for a range):

global (outside) 1 -

The NAT guide is pretty decent at explaining it (but can be confusing at times), so let me know if you have more questions:



This Discussion