Cisco ASA 5505 Configuration Manual page 524

Asa 5500 series
Hide thumbs Also See for ASA 5505:
Table of Contents

Advertisement

Licensing Requirements for Network Object NAT
Licensing Requirements for Network Object NAT
The following table shows the licensing requirements for this feature:
Model
License Requirement
All models
Base License.
Prerequisites for Network Object NAT
Depending on the configuration, you can configure the mapped address inline if desired or you can create
a network object or network object group for the mapped address. Network object groups are particularly
useful for creating a mapped address pool with discontinous IP address ranges or multiple hosts or
subnets. To create a network object or group, see the
on page
For specific guidelines for objects and groups, see the configuration section for the NAT type you want
to configure. See also the
Guidelines and Limitations
This section includes the guidelines and limitations for this feature.
Context Mode Guidelines
Supported in single and multiple context mode.
Firewall Mode Guidelines
IPv6 Guidelines
Does not support IPv6.
Additional Guidelines
Cisco ASA 5500 Series Configuration Guide using ASDM
27-2
13-1.
"Guidelines and Limitations"
Supported in routed and transparent firewall mode.
In transparent mode, you must specify the real and mapped interfaces; you cannot use --Any--.
In transparent mode, you cannot configure interface PAT, because the transparent mode interfaces
do not have IP addresses. You also cannot use the management IP address as a mapped address.
If you change the NAT configuration, and you do not want to wait for existing translations to time
out before the new NAT information is used, you can clear the translation table using the clear xlate
command. However, clearing the translation table disconnects all current connections that use
translations.
If you remove a dynamic NAT or PAT rule, and then add a new rule with mapped addresses
Note
that overlap the addresses in the removed rule, then the new rule will not be used until all
connections associated with the removed rule time out or are cleared using the clear xlate
command. This safeguard ensures that the same address is not assigned to multiple hosts.
Chapter 27
Configuring Network Object NAT
"Configuring Network Objects and Groups" section
section.
OL-20339-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Asa 5510Asa 5540Asa 5520Asa 5550Asa 5580

Table of Contents