Cisco Catalyst 6500 Series Configuration Manual page 166

Catalyst 6500 series switch and cisco 7600 series router firewall services
Hide thumbs Also See for Catalyst 6500 Series:
Table of Contents

Advertisement

Using Dynamic NAT and PAT
NAT ID (see
uses a static NAT statement to allow outside access, so both the source and destination addresses are
translated.
Figure 9-13 Outside NAT and Inside NAT Combined
Global 1: 10.1.2.30-
See the following commands for this example:
FWSM/contexta(config)# nat (dmz) 1 10.1.1.0 255.255.255.0 outside
FWSM/contexta(config)# nat (dmz) 1 10.1.1.0 255.255.255.0
FWSM/contexta(config)# static (inside,dmz) 10.1.2.27 10.1.1.5 netmask 255.255.255.255
FWSM/contexta(config)# global (outside) 1 209.165.201.3-209.165.201.4
FWSM/contexta(config)# global (inside) 1 10.1.2.30-1-10.1.2.40
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide
9-22
Figure
9-13). Note that for outside NAT (DMZ interface to Inside interface), the inside host
Outside
10.1.1.15
Global 1: 209.165.201.3-
209.165.201.10
Outside NAT 1: 10.1.1.0/24
NAT 1: 10.1.1.0/24
10.1.2.40
Static to DMZ: 10.1.2.27
Inside
10.1.2.27
Chapter 9
Source Addr Translation
209.165.201.4
DMZ
10.1.1.15
10.1.1.5
Source Addr Translation
10.1.1.15
10.1.2.30
Dest. Addr Translation
10.1.1.5
10.1.2.27
Configuring Network Address Translation
OL-6392-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

7600 series

Table of Contents