Contents
v
Cisco ASA Series Firewall CLI Configuration Guide
Main Differences Between Network Object NAT and Twice NAT 3-13
Information About Network Object NAT 3-14
Information About Twice NAT 3-14
NAT Rule Order 3-18
NAT Interfaces 3-19
Routing NAT Packets 3-19
Mapped Addresses and Routing 3-19
Transparent Mode Routing Requirements for Remote Networks 3-21
Determining the Egress Interface 3-22
NAT for VPN 3-22
NAT and Remote Access VPN 3-23
NAT and Site-to-Site VPN 3-24
NAT and VPN Management Access 3-26
Troubleshooting NAT and VPN 3-28
DNS and NAT 3-28
Where to Go Next 3-33
CHAPTER
4Configuring Network Object NAT 4-1
Information About Network Object NAT 4-1
Licensing Requirements for Network Object NAT 4-2
Prerequisites for Network Object NAT 4-2
Guidelines and Limitations 4-2
Default Settings 4-3
Configuring Network Object NAT 4-4
Adding Network Objects for Mapped Addresses 4-4
Configuring Dynamic NAT 4-5
Configuring Dynamic PAT (Hide) 4-7
Configuring Static NAT or Static NAT-with-Port-Translation 4-11
Configuring Identity NAT 4-14
Configuring Per-Session PAT Rules 4-16
Monitoring Network Object NAT 4-17
Configuration Examples for Network Object NAT 4-18
Providing Access to an Inside Web Server (Static NAT) 4-19
NAT for Inside Hosts (Dynamic NAT) and NAT for an Outside Web Server (Static NAT) 4-19
Inside Load Balancer with Multiple Mapped Addresses (Static NAT, One-to-Many) 4-21
Single Address for FTP, HTTP, and SMTP (Static NAT-with-Port-Translation) 4-22
DNS Server on Mapped Interface, Web Server on Real Interface (Static NAT with DNS
Modification) 4-23