3-36
Cisco ASA Series Firewall ASDM Configuration Guide
Chapter3 Information About NAT (ASA 8.3 and Later)
Where to Go Next
Figure 3-30 shows an FTP server and DNS server on the outside. The ASA has a static translation for
the outside server. In this case, when an inside user performs a reverse DNS lookup for 10.1.2.56, the
ASA modifies the reverse DNS query with the real address, and the DNS server responds with the server
name, ftp.cisco.com.
Figure3-30 PTR Modification, DNS Server on Host Network
Where to Go Next
To configure network object NAT, see Chapter4, “Configuring Network Object NAT (ASA 8.3 and
Later).”
To configure twice NAT, see Chapter5, “Configuring Twice NAT (ASA 8.3 and Later).”
ftp.cisco.com
209.165.201.10
DNS Server
Outside
Inside
User
10.1.2.27
Static Translation on Inside to:
10.1.2.56
1
2
4
3
Reverse DNS Query
209.165.201.10
Reverse DNS Query Modification
209.165.201.1010.1.2.56
PTR Record
ftp.cisco.com
ASA
Reverse DNS Query
10.1.2.56?
304002