28-7
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 28 Configuring Twice NAT
Configuring Twice NAT
Figure 28-8 NAT Options
a.
Check the Enable rule check box to enable this NAT rule. The rule is enabled by default.
b. (For a source-only rule) To rewrite the DNS A record in DNS replies, check the Translate DNS
replies that match this rule check box.
Be sure DNS inspection is enabled (it is enabled by default). You cannot configure DNS
modification if you configure a destination address. See the “DNS and NAT” section on page 26-21
for more information.
c. In the Description field, add a description about the rule up to 200 characters in length.
Step 10 Click OK.
Configuring Dynamic PAT (Hide)
This section describes how to configure a dynamic PAT (hide) rule using twice NAT. For more
information about dynamic PAT, see the “Dynamic PAT” section on page 26-10.
Detailed Steps
To configure dynamic PAT, perform the following steps:
Step 1 Choose Configuration > Firewall > NAT Rules, and then click Add.
If you want to add this rule to section 3 after the network object rules, then click the down arrow next to
Add, and choose Add NAT Rule After Network Object NAT Rules.
Figure 28-9 Adding a NAT Rule
The Add NAT Rule dialog box appears.