EasyManua.ls Logo

Cisco ASA 5515-X

Cisco ASA 5515-X
2164 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
1-15
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the Transparent or Routed Firewall
Firewall Mode Examples
An Inside User Visits a Web Server
Figure 1-3 shows an inside user accessing an outside web server.
Figure 1-3 Inside to Outside
The following steps describe how data moves through the ASA (see Figure 1-3):
1. The user on the inside network requests a web page from www.example.com.
2. The ASA receives the packet and because it is a new session, the ASA verifies that the packet is
allowed according to the terms of the security policy (access lists, filters, AAA).
For multiple context mode, the ASA first classifies the packet to a context.
3. The ASA translates the local source address (10.1.2.27) to the global address 209.165.201.10, which
is on the outside interface subnet.
The global address could be on any subnet, but routing is simplified when it is on the outside
interface subnet.
4. The ASA then records that a session is established and forwards the packet from the outside
interface.
5. When www.example.com responds to the request, the packet goes through the ASA, and because
the session is already established, the packet bypasses the many lookups associated with a new
connection. The ASA performs NAT by untranslating the global destination address to the local user
address, 10.1.2.27.
6. The ASA forwards the packet to the inside user.
Web Server
10.1.1.3
www.example.com
User
10.1.2.27
209.165.201.2
10.1.1.110.1.2.1
Source Addr Translation
209.165.201.1010.1.2.27
Outside
Inside DMZ
92404

Table of Contents

Other manuals for Cisco ASA 5515-X

Related product manuals