20-4
Cisco ASDM User Guide
OL-16647-01
Chapter 20 Configuring Access Rules and EtherType Rules
Information About Access Rules and EtherType Rules
IP Addresses Used for Access Rules When You Use NAT
When you use NAT, the IP addresses you specify for an access rule depend on the interface to which the
access rule is attached; you need to use addresses that are valid on the network connected to the interface.
This guideline applies for both inbound and outbound access rules: the direction does not determine the
address used, only the interface does.
For example, you want to apply an access rule to the inbound direction of the inside interface. You
configure the security appliance to perform NAT on the inside source addresses when they access outside
addresses. Because the access rule is applied to the inside interface, the source addresses are the original
untranslated addresses. Because the outside addresses are not translated, the destination address used in
the access rule is the real address (see Figure 20-2).
Figure 20-2 IP Addresses in Access Rules: NAT Used for Source Addresses
209.165.200.225
Inside
Outside
Inbound ACL
Permit from 10.1.1.0/24 to 209.165.200.225
10.1.1.0/24
PAT
209.165.201.4:port10.1.1.0/24
104634