Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Public IP addresses on DMZ (SA520)


I just bought an SA520 to replace my existing FW.

The thing is that I have private IP adresses on my LAN, and I have been issued a public IP network for my DMZ by my ISP.

Meaning I want to NAT my LAN but not my DMZ, but I can't seem to find a way in the 520 to do that. I can only find the oprion to turn off NAT all together.

Anyone know how to do this?


Everyone's tags (4)
New Member

Public IP addresses on DMZ (SA520)

YOu can configure different types of NAT on ASA5520,

As you mentioned that you have a public ip address rage alloted for the internal uses you can bypass nat all together as well.

Please refer to the following link for more information on configuring NAT, it is must to understand what we are doing first

A quick suggestin to use PAT.

Since your inside users wants to go to outside network I believe via OUTSIDE Interface only!!!

you can use the following commands

nat (inside) 1

global (outside) 1 interface

1 is the NAT-ID here

it can be different as well, change it to any number if already used.

Please post if there are other specific questions.


CreatePlease login to create content