5-4

Cisco ASA 5500 Series Configuration Guide using the CLI
Chapter5 Configuring Multiple Context Mode
Information About Security Contexts

NAT Configuration

If you do not use unique MAC addresses, then the mapped addresses in your NAT configuration are used

to classify packets. We recommend using MAC addresses instead of NAT, so that traffic classification

can occur regardless of the completeness of the NAT configuration.

Classification Examples

Figure 5-1 shows multiple contexts sharing an outside interface. The classifier assigns the packet to

Context B because Context B includes the MAC address to which the router sends the packet.

Figure5-1 Packet Classification with a Shared Interface using MAC Addresses
Classifier
Context A Context B
MAC 000C.F142.4CDCMAC 000C.F142.4CDBMAC 000C.F142.4CDA
GE 0/1.3GE 0/1.2
GE 0/0.1 (Shared Interface)
Admin
Context
GE 0/1.1
Host
209.165.201.1
Host
209.165.200.225
Host
209.165.202.129
Packet Destination:
209.165.201.1 via MAC 000C.F142.4CDC
Internet
Inside
Customer A
Inside
Customer B
Admin
Network
153367