05-14-2014 06:54 AM - edited 03-11-2019 09:12 PM
I have ASA 5510 with 8.4(2) version.
I need help to create 2 dynamic NAT for 2 interface. Here is what I have.
Outside interface
Inside interface
DMZ interface
backup interface
Here is my nat
object network DMZ-10.1.8.0_24
nat (dmz,outside) dynamic interface
object network INSIDE-10.1.7.0_24
nat (inside,outside) dynamic interface
I want to add additional NAT like
"object network INSIDE-10.1.7.0_24
nat (inside,backup) dynamic interface"
But it does not allow me to add, once I add, it removes "nat (inside,outside) dynamic interface". My goal is to achieve inside network and dmz network to translate backup network interface without affecting current outside NAT. backup interface is private network which connect to different network with other untrusted connections connect to that network. Thanks in advance for your advice.
Solved! Go to Solution.
05-14-2014 10:28 AM
You need to create another object, with the same IP address and use this new object for nat. Exemple
INSIDE-10.1.7.0_24-2
subnet 10.1.7.0 255.255.255.0
nat (inside,backup) dynamic interface
Also if the backup interface has the same security level of the inside interface you need to allow the traffic explicitly because it's denied by default. Use the command
same-security-traffic permit inter-interface
05-14-2014 07:12 AM
OK, dumb question, but does the backup interface have an IP address and security level assigned?
05-14-2014 08:30 AM
Hi Colin,
Thanks for your reply. Yes backup interface has same security level as outside and it has ip assigned.
05-14-2014 10:28 AM
You need to create another object, with the same IP address and use this new object for nat. Exemple
INSIDE-10.1.7.0_24-2
subnet 10.1.7.0 255.255.255.0
nat (inside,backup) dynamic interface
Also if the backup interface has the same security level of the inside interface you need to allow the traffic explicitly because it's denied by default. Use the command
same-security-traffic permit inter-interface
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: