Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

NAT help

Hi,

I have a Cisco ASA 5520, I have a 3750 with VLAN's connected to the firewall and one of these VLAN's is a remote network.

At the moment their router is not managed by us and this remote LAN uses one of our DHCP servers within the firewalls inside interface.

I have now got a 2nd DHCP server which I need them to use and don't want to pay the money to get this DHCP helper to point to the new server, can I crate a NAT?

So they will still try and get their DHCP requests from 192.168.21.1 but really they are going to 192.168.21.10?

Thanks

5 REPLIES

Re: NAT help

A static NAT might help here.

Which incoming interface of DHCP request is on ASA? From outside?

How the remote LAN is connected to this ASA? via VPN?

Posted current configuration if possible.

New Member

Re: NAT help

You can do one of a couple of things.. You can use the firewall to provide DHCP addresses and forget the DHCP server or sure you can nat. I just tested this and from a config perspective it takes.. Didn't try to pass data through but would look something like..

static (inside,(unmanaged_net) 192.168.21.1 192.168.21.10 netmask 255.255.255.255 0 0

Then just allow the DHCP rule inbound which you probably already have anyway.

Let me know if that works. I can't verify the operation on the firewall from where I am but the principle should work.

You're just saying that anyone on that network wanting a DHCP address go to this next hop (firewall ip) but now taht firewall has a nat rule so it should arp for that address on that network.

New Member

Re: NAT help

Hi,

Shouldn't static (inside,(unmanaged_net) 192.168.21.1 192.168.21.10 netmask 255.255.255.255 0 0

be

static (inside,(unmanaged_net) 192.168.21.10 192.168.21.1 netmask 255.255.255.255 0 0

As the unmanged LAN currently gets DHCP requests from 192.168.21.1 but needs them translated to 192.168.21.10?

Thanks

New Member

Re: NAT help

He wants the address on the unmanaged net to stay as it is so it's right.

New Member

Re: NAT help

Sorry it's just my understanding as I am just viewing it on the ASDM (after adding the rule in the CLI) under NAT Rules > "inside" it shows type as static, original source 192.168.21.10 translate interface "unmanaged_LAN" address 192.168.21.1.

I'm going to give it some testing now.

Thanks again

101
Views
0
Helpful
5
Replies