Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Can the ASA perform SNAT?

SNAT as in "Source NAT".  I'm trying to setup dual firewalls and want to use both concurrently while I transition my inbound NAT rules to the ASA.  However, the default route on the core switch prohibits me from doing this since it only knows about the old firewall.  A couple of possible workarounds are SNAT or Policy Based Routing on the core switch.  Can the ASA perform SNAT like F5?  i.e, Can it use its internal address as the "source" for anything destined to an internal web server?  That way the web server would attempt to return the packet back to the ASA instead of using the default route, which is the old firewall.  I've attached a simplified diagram of what I'm trying to accomplish.  Thanks! 

Everyone's tags (3)
1 ACCEPTED SOLUTION

Accepted Solutions

Can the ASA perform SNAT?

Hello David,

Thanks for taking the time to let the forum about this resolution

Now please mark the question as answered so future users can learn as you did

Have a wonderful night

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
2 REPLIES
New Member

Can the ASA perform SNAT?

One of the TAC guys helped me wth this.  The answer is YES!  The following line did the trick for me.

nat (outside,inside) source dynamic any interface destination static "Your Public mapped IP address here" "Your Internal real www server IP address here"

Can the ASA perform SNAT?

Hello David,

Thanks for taking the time to let the forum about this resolution

Now please mark the question as answered so future users can learn as you did

Have a wonderful night

Julio

Julio Carvajal
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
1279
Views
0
Helpful
2
Replies
CreatePlease to create content