32-27
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter32 Information About NAT (ASA 8.3 and Later)
Where to Go Next
Figure 32-24 shows a web server and DNS server on the outside. The ASA has a static translation for
the outside server. In this case, when an inside user requests the address for ftp.cisco.com from the DNS
server, the DNS server responds with the real address, 209.165.20.10. Because you want inside users to
use the mapped address for ftp.cisco.com (10.1.2.56) you need to configure DNS reply modification for
the static translation.
Figure32-24 DNS Reply Modification, DNS Server on Host Network
Where to Go Next
To configure network object NAT, see Chapter33, “Configuring Network Object NAT (ASA 8.3 and
Later).”
To configure twice NAT, see Chapter34, “Configuring Twice NAT (ASA 8.3 and Later).”
ftp.cisco.com
209.165.201.10
DNS Server
Outside
Inside
User
10.1.2.27
Static Translation on Inside to:
10.1.2.56
130022
1
2
7
6
5
4
3
DNS Query
ftp.cisco.com?
DNS Reply
209.165.201.10
DNS Reply Modification
209.165.201.10 10.1.2.56
DNS Reply
10.1.2.56
FTP Request
209.165.201.10
Dest Addr. Translation
209.165.201.1010.1.2.56
FTP Request
10.1.2.56
Security
Appliance