We help IT Professionals succeed at work.

NAT by destination IP

mw-hosting
mw-hosting asked
on
Is there a way to NAT an IP depending on the destination IP?

I have a load balancer that sends data out one IP no matter what LB pool the data comes from.

Example of what I want:  
data from 10.2.0.20 dest 63.x.x.x/24 - NAT IP to 172.1.0.20 (vpn#1)
data from 10.2.0.20 dest 85.x.x.x/24 - NAT IP to 192.168.1.20 (vpn#2)
-Any port (80, 443, etc...)
Comment
Watch Question

Commented:
You can create a static NAT

63.x.x.x <--> 172.1.0.20
85.x.x.x <--> 192.168.1.20
Sr Software Engineer
Commented:
what you want is called policy based natting.  it works like such:

access-list path1 permit ip host 10.2.0.20 63.x.x.x 255.255.255.0
access-list path2 permit ip host 10.2.0.20 85.x.x.x 255.255.255.0

static (inside,outside) 172.1.0.20 access-list path1
static (inside,outside) 192.168.1.20 access-list path2

this will NAT 10.2.0.20 to 172.1.0.20 if the traffic is going to any 63.x.x.x/24 IP and to 192.168.1.20 if going to any 85.x.x.x/24 IP.  I'm not 100% on the syntax, but its roughly like that for policy-based natting