Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

1921 behind an asa 5505

Hello - I have a 1921 with IPBASEK9 v15.2 software and an ASA 5505 v9.0(4) with a Security Plus License.  There will be 4 VLANs/subnets behind the 1921 but only one subnet will need to reach the Internet.  

 

My question is what is the best way to configure the ASA to provide NAT for the one subnet needing Internet access?

1 REPLY

Hi ,

Hi ,

 From your connectvity diagram 1921 router is behind asa .

 ASA<--> Router<-> VLAN 

a) Use x.x.x.x/27 or x.x.x.x/28 network subnet for connectvity asa to 1921 router 

b) Create 4 Vlan on your 1921 router .

3) Point reverse route from your asa to router for newly created subnets 

4) PAT only the subnet which you need to give internet access ( Like if you have created 192.168.1.0/24 ,192.168.2.0/24 ,192.168.3.0/24 ,192.168.4.0/24  

over here i am PATing only for 192.168.1.0/24

if your asa is running with asa code 8.3

global (outside) 1 interface 

nat (inside) 1 192.168.1.0 255.255.255.0

 

If you running with asa code above 8.3

object network obj-192.168.1.0
   subnet 192.168.1.0 255.255.255.0
   nat (inside,outside) dynamic interface 

Let me know if any support needed on this 

HTH

Sandy

 

38
Views
0
Helpful
1
Replies