cisco ASA 5505

How to configure cisco ASA 5505 NAT between two hosts/machines?
Who is Participating?
batry_boyConnect With a Mentor Commented:
Assuming the following values:

inside native IP address -
outside translated IP address -

Here is the command to translate the inside host at to when sending traffic to any host on the outside interface:

static (inside,outside) netmask

If you want to translate that same inside host for traffic going to a host in a dmz network and you want to use it's own native IP address ( for the translation, then you can use:

static (inside,dmz) netmask

In this fashion, any machine on the dmz subnet will see the inside host as it's native IP address.
harbor235Connect With a Mentor Commented:

You must be running 7.x or 8.x code on this ASA so make sure the following is also in place.

make sure you have the command "nat-control" in your config, otherwise the above config
commands will not work. Nat-control is disabled by default. Also, if you want NAT overload on the outside interface the above config will need some additional commands.

for instance;

nat (inside) 1
global (outside) 1 interface

Also, do not forget to add appropriate access-lists if outside initiated traffic is allowed in.

Here is a good doc:

HARBOR235 ;}

harbor235 ;}

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.