10-3
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 10 NAT Examples and Reference
Examples for Network Object NAT
Figure 10-2 Dynamic NAT for Inside, Static NAT for Outside Web Server
Procedure
Step 1 Create a network object for the dynamic NAT pool to which you want to translate the inside addresses.
hostname(config)# object network myNatPool
hostname(config-network-object)# range 209.165.201.20 209.165.201.30
Step 2 Create a network object for the inside network.
hostname(config)# object network myInsNet
hostname(config-network-object)# subnet 10.1.2.0 255.255.255.0
Step 3 Enable dynamic NAT for the inside network using the dynamic NAT pool object.
hostname(config-network-object)# nat (inside,outside) dynamic myNatPool
Step 4 Create a network object for the outside web server.
hostname(config)# object network myWebServ
hostname(config-network-object)# host 209.165.201.12
Step 5 Configure static NAT for the web server.
hostname(config-network-object)# nat (outside,inside) static 10.1.2.20
Outside
Inside
10.1.2.1
209.165.201.1
Security
Appliance
myInsNet
10.1.2.0/24
Web Server
209.165.201.12
209.165.201.12 10.1.2.20
248773
Undo Translation
10.1.2.10 209.165.201.20
Translation