Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Cisco: NSP

help with NAT on ASA 8.3+

 

 

Cisco nsp RSS feed   Index | Next | Previous | View Threaded


svoll.voip at gmail

Aug 7, 2012, 7:10 AM

Post #1 of 2 (343 views)
Permalink
help with NAT on ASA 8.3+

I have a LAN to LAN connection (say 10.10.1.x/24) that terminates on my ASA
8.3+.

I have a internal IP address on the inside of 10.10.0.1 that because of DNS
needs to look like 172.17.1.1.

So client at remote site 10.10.1.250 gets DNS for 172.17.1.1 but should be
NAT'd and connecting to 10.10.0.1. How do I setup the NAT in 8.3+?

10.10.1.x looks to be on the outside interface and 10.10.0.1 looks to be on
the inside interface.

TIA

Scott
_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


rwest at zyedge

Aug 7, 2012, 7:53 AM

Post #2 of 2 (356 views)
Permalink
Re: help with NAT on ASA 8.3+ [In reply to]

Double NAT.

Should look something like this:

nat (inside,outside) source static obj_10.10.0.1 obj_172.17.1.1 destination static obj_10.10.1.0 obj_10.10.1.0

Since this equivalent to static policy nat in 8.2 and below, make sure you position this nat rule near the top.

Sent from handheld

On Aug 7, 2012, at 10:12 AM, "Scott Voll" <svoll.voip [at] gmail> wrote:

> I have a LAN to LAN connection (say 10.10.1.x/24) that terminates on my ASA
> 8.3+.
>
> I have a internal IP address on the inside of 10.10.0.1 that because of DNS
> needs to look like 172.17.1.1.
>
> So client at remote site 10.10.1.250 gets DNS for 172.17.1.1 but should be
> NAT'd and connecting to 10.10.0.1. How do I setup the NAT in 8.3+?
>
> 10.10.1.x looks to be on the outside interface and 10.10.0.1 looks to be on
> the inside interface.
>
> TIA
>
> Scott
> _______________________________________________
> cisco-nsp mailing list cisco-nsp [at] puck
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Cisco nsp RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.