20-5
Cisco ASDM User Guide
OL-16647-01
Chapter 20 Configuring Access Rules and EtherType Rules
Information About Access Rules and EtherType Rules
If you want to allow an outside host to access an inside host, you can apply an inbound access rule on
the outside interface. You need to specify the translated address of the inside host in the access rule
because that address is the address that can be used on the outside network (see Figure 20-3).
Figure 20-3 IP Addresses in Access Rules: NAT used for Destination Addresses
If you perform NAT on both interfaces, keep in mind the addresses that are visible to a given interface.
In Figure 20-4, an outside server uses static NAT so that a translated address appears on the inside
network.
Figure 20-4 IP Addresses in Access Rules: NAT used for Source and Destination Addresses
209.165.200.225
Inside
Outside
Static NAT
209.165.201.510.1.1.34
ACL
Permit from 209.165.200.225 to 209.165.201.5
104636
209.165.200.225
10.1.1.0/24
Inside
Outside
Static NAT
10.1.1.56
ACL
Permit from 10.1.1.0/24 to 10.1.1.56
PAT
209.165.201.4:port10.1.1.0/24
104635