Solved

NAT on Cisco ASA

Posted on 2014-02-17
4
552 Views
Last Modified: 2014-02-18
HI

I have to nat entries on my asa firewall.

Nat (inside,outside) source static pc_01 interface
Nat (inside,outside) source static pc_02

Object network pc_01
host 192.168.1.1
Object network pc_02
host 192.168.1.2

Only one nat entire works at a time basically the first entry.
How can I make both work?
0
Comment
Question by:ciscosupp
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 9

Expert Comment

by:ffleisma
ID: 39866196
basically you are statically NATing pc_01 to outside interface IP, which is one is to one NAT translation. that is why the second one is not working. use dynamic NAT

Try the following:

no nat (inside,outside) source static pc_01 interface
no nat (inside,outside) source static pc_02

nat (inside,outside) source dynamic pc_01 interface
nat (inside,outside) source dynamic pc_02 interface
0
 

Author Comment

by:ciscosupp
ID: 39866496
Thanks it works but does the Nat statement still mean only 192.168.1.1 and 192.168.1.2 is nated to outside. Please advice
0
 
LVL 9

Accepted Solution

by:
ffleisma earned 500 total points
ID: 39866979
yes it means, only both 192.168.1.1 and 192.168.1.2 are NATed to the ouside interface IP.

If you need the entire subnet 192.168.1.x/24, it would look something like this.

object network obj_192.168.1.0-24
 subnet 192.168.1.0 255.255.255.0

nat (inside,outside) source dynamic obj_192.168.1.0-24 interface

let me know if this helps or if you need something different.
0
 

Author Closing Comment

by:ciscosupp
ID: 39867008
thanks perfect :-)
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I recently updated from an old PIX platform to the new ASA platform.  While upgrading, I was tremendously confused about how the VPN and AnyConnect licensing works.  It turns out that the ASA has 3 different VPN licensing schemes. "site-to-site" …
This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question