1-22
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring Twice NAT
Configuring Twice NAT
Detailed Steps
Command Purpose
Step 1
Create network objects or groups for the:
• Source real addresses (you will typically use
the same object for the source mapped
addresses)
• Destination real addresses
• Destination mapped addresses
See the “Adding Network Objects for Real and Mapped
Addresses” section on page 1-4.
If you want to perform identity NAT for all addresses, you can
skip creating an object for the the source real addresses and
instead use the keywords any any in the nat command.
If you want to configure destination static interface NAT with port
translation only, you can skip adding an object for the destination
mapped addresses, and instead specify the interface keyword in
the nat command.
Step 2
(Optional) Create service objects for the:
• Source or Destination real ports
• Source or Destination mapped ports
See the “(Optional) Adding Service Objects for Real and Mapped
Ports” section on page 1-6.