18-17
Cisco Router and Security Device Manager Version 2.2 Users Guide
OL-4015-08
Chapter18 Network Addres s Translation
Network Address Translation Rules

Port Address Translation (PAT)

There may be times when most of the addresses in th e pool have been assigned,
and the IP address pool is nearly depleted. When this occurs, PAT can be used with
a single IP address to satisfy additional requests for IP addresse s. Check this box
if you want the router to use PAT when the address pool is close to depletion.
IP Address
Enter the lowest numbered IP address in the range in the left field; enter the
highest numbered IP address in the range in the right field. For more information,
refer to Available Interface Configurations.
Network Mask
Enter the subnet mask or the number of network bits that spe cify how many bits
in the IP addresses are network bits.
Add or Edit Static Address Translation Rule: Inside to Outside
Use this help topic when you have chosen direction From Ins ide to Outside in
the Add or the Edit Static Address Translation Rule window.
Use this window to add or edit a static address translation rule. If you are editing
a rule, the rule type, static or dynamic, and the direc tion are disabled. If you need
to change these settings, delete the rule, and recreate it using the settings you
want.
There are two types of static address translations using NAT, simple static and
extended static .
Note If you create a NAT rule that would translate addresses of devices that are part of
a VPN, SDM will prompt you to allow it to create a route map that protects those
addresses from being translated by NAT. If NAT is allowed to translate addresses
of devices on a VPN, their translated addresses will not match the IPSec rule used
in the IPSec policy, and traffic will be sent unencrypted. You can view route maps
created by SDM or created using the CLI by clicking the View Route Maps button
in the NAT window.