34-22
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter34 Configuring Twice NAT (ASA 8.3 and Later)
Configuring Twice NAT
Step9 (Optional) Configure NAT options in the Options area.
a. Enable rule —Enables this NAT rule. The rule is enabled by default.
b. (For a source-only rule) Translate DNS replies that match this rule—Rewrites the DNS A record in
DNS replies. Be sure DNS inspection is enabled (it is enabled by default). You cannot configure
DNS modification if you configure a destination address. See the “DNS and NAT” section on
page 32-24 for more information.
c. Disable Proxy ARP on egress interface—Disables proxy ARP for incoming packets to the mapped
IP addresses. See the “Mapped Addresses and Routing” section on page32-22 for more
information.Direction—To make the rule unidirectional, choose Unidirectional. The default is
Both. Making the rule unidirectional prevents traffic from initiating connections to the real
addresses. You might want to use this setting for testing purposes.
d. Description—Adds a description about the rule up to 200 characters in length.
Step10 Click OK.
Configuring Identity NAT
This section describes how to configure an identity NAT rule using twice NAT. For more information
about identity NAT, see the “Identity NAT” section on page32-11.
Detailed Steps
To configure identity NAT, perform the following steps:
Step1 Choose Configuration > Firewall > NAT Rules, and then click Add.
If you want to add this rule to section 3 after the network object rules, then click the down arrow next to
Add, and choose Add NAT Rule After Network Object NAT Rules.