Cisco Systems ASA 5505, ASA 5545-X, ASA 5555-X Platform Feature Name Releases Feature Information

Models: ASA Services Module ASA 5555-X ASA 5545-X ASA 5585-X ASA 5580 ASA 5505

1 754
Download 754 pages 55.66 Kb
Page 186
Image 186

Chapter 5 Configuring Twice NAT (ASA 8.3 and Later)

Feature History for Twice NAT

Table 5-1

Feature History for Twice NAT (continued)

 

 

 

 

 

 

 

Platform

 

Feature Name

 

Releases

Feature Information

 

 

 

Automatic NAT rules to translate a VPN peer’s

8.4(3)

In rare situations, you might want to use a VPN peer’s real

local IP address back to the peer’s real IP

 

IP address on the inside network instead of an assigned local

address

 

 

IP address. Normally with VPN, the peer is given an

 

 

 

assigned local IP address to access the inside network.

 

 

 

However, you might want to translate the local IP address

 

 

 

back to the peer’s real public IP address if, for example,

 

 

 

your inside servers and network security is based on the

 

 

 

peer’s real IP address.

 

 

 

You can enable this feature on one interface per tunnel

 

 

 

group. Object NAT rules are dynamically added and deleted

 

 

 

when the VPN session is established or disconnected. You

 

 

 

can view the rules using the show nat command.

 

 

 

Note Because of routing issues, we do not recommend

 

 

 

using this feature unless you know you need this

 

 

 

feature; contact Cisco TAC to confirm feature

 

 

 

compatibility with your network. See the following

 

 

 

limitations:

 

 

 

Only supports Cisco IPsec and AnyConnect Client.

 

 

 

Return traffic to the public IP addresses must be

 

 

 

routed back to the ASA so the NAT policy and VPN

 

 

 

policy can be applied.

 

 

 

Does not support load-balancing (because of

 

 

 

routing issues).

 

 

 

Does not support roaming (public IP changing).

 

 

 

ASDM does not support this command; enter the command

 

 

 

using the Command Line Tool.

 

 

 

NAT support for IPv6

9.0(1)

NAT now supports IPv6 traffic, as well as translating

 

 

 

between IPv4 and IPv6. Translating between IPv4 and IPv6

 

 

 

is not supported in transparent mode.

 

 

 

We modified the following screen: Configuration > Firewall

 

 

 

> NAT Rules.

 

 

 

 

Cisco ASA Series Firewall ASDM Configuration Guide

5-50

Page 186
Image 186
Cisco Systems ASA 5505, ASA 5545-X, ASA 5555-X, ASA 5585-X, ASA 5580 manual Platform Feature Name Releases Feature Information