Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium


cisco ASA 5505

Posted on 2007-11-14
Medium Priority
Last Modified: 2012-10-21
How to configure cisco ASA 5505 NAT between two hosts/machines?
Question by:nsamri
LVL 28

Accepted Solution

batry_boy earned 500 total points
ID: 20285991
Assuming the following values:

inside native IP address -
outside translated IP address -

Here is the command to translate the inside host at to when sending traffic to any host on the outside interface:

static (inside,outside) netmask

If you want to translate that same inside host for traffic going to a host in a dmz network and you want to use it's own native IP address ( for the translation, then you can use:

static (inside,dmz) netmask

In this fashion, any machine on the dmz subnet will see the inside host as it's native IP address.
LVL 32

Assisted Solution

harbor235 earned 500 total points
ID: 20290868

You must be running 7.x or 8.x code on this ASA so make sure the following is also in place.

make sure you have the command "nat-control" in your config, otherwise the above config
commands will not work. Nat-control is disabled by default. Also, if you want NAT overload on the outside interface the above config will need some additional commands.

for instance;

nat (inside) 1
global (outside) 1 interface

Also, do not forget to add appropriate access-lists if outside initiated traffic is allowed in.

Here is a good doc:


HARBOR235 ;}

harbor235 ;}


Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
There’s a movement in Information Technology (IT), and while it’s hard to define, it is gaining momentum. Some call it “stream-lined IT;” others call it “thin-model IT.”
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

577 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question