Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
Community Member

Cisco ASA : Two inside interfaces and NAT/Port forwards.

Due to having two routers on the inside of an ASA running HSRP for fail over purposes I have two inside interfaces. For example:


Int GE0/0 : (outside)
Int GE0/1 : (inside1)
Int GE0/2 : (inside2)

Cisco Router Primary
Int GE0/0 :
Int GE0/1 : (standby IP)
Int GE0/2 : (standby IP)

Cisco Router backup
Int GE0/0 :
Int GE0/1 : (standby IP)
Int GE0/2 : (standby IP)

Due to the the way the failover works traffic could come into the ASA via either the "inside" or "inside2" interface.

When setting NAT and port forwards you have to specify the inside and outside interface for it to work. I don't want to have to remove and re-apply all the port forwards if the primary router fails and traffic starts to come into the ASA on the inside2 interface.

Is there an easier way to do this?



You don't need to remove the

You don't need to remove the NAT commands for the inside interface when it has failed.  Why not just have two sets of NAT commands that are exactly the same, except one set references inside1 and the other references inside2?


Please remember to select a correct answer and rate helpful posts


Please remember to rate and select a correct answer
CreatePlease to create content