4-21
Cisco ASA Series Firewall CLI Configuration Guide
Chapter4 Configuring Network Object NAT
Configuration Examples for Network Object NAT
Inside Load Balancer with Multiple Mapped Addresses (Static NAT, One-to-Many)
The following example shows an inside load balancer that is translated to multiple IP addresses. When
an outside host accesses one of the mapped IP addresses, it is untranslated to the single load balancer
address. Depending on the URL requested, it redirects traffic to the correct web server. (See Figure 4-3).
Figure4-3 Static NAT with One-to-Many for an Inside Load Balancer
Step1 Create a network object for the addresses to which you want to map the load balancer:
ciscoasa(config)# object network myPublicIPs
ciscoasa(config-network-object)# range 209.165.201.3 209.265.201.8
Step2 Create a network object for the load balancer:
ciscoasa(config)# object network myLBHost
Step3 Define the load balancer address:
ciscoasa(config-network-object)# host 10.1.2.27
Step4 Configure static NAT for the load balancer:
ciscoasa(config-network-object)# nat (inside,outside) static myPublicIPs
Host
Outside
Inside
Load Balancer
10.1.2.27
Web Servers
Undo Translation
10.1.2.27209.165.201.3
Undo Translation
10.1.2.27209.165.201.4
Undo Translation
10.1.2.27209.165.201.5
248633