Cisco ASA Series Configuration Manual page 186

Firewall cli, asa services module, and the adaptive security virtual appliance
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

Static NAT
The following figure shows a typical static NAT with port translation scenario showing both a port that
is mapped to itself and a port that is mapped to a different value; the IP address is mapped to a different
value in both cases. The translation is always active so both translated and remote hosts can initiate
connections.
Figure 9-6
10.1.1.2:8080
For applications that require application inspection for secondary channels (for example, FTP and VoIP),
Note
the ASA automatically translates the secondary ports.
Static NAT with Identity Port Translation
The following static NAT with port translation example provides a single address for remote users to
access FTP, HTTP, and SMTP. These servers are actually different devices on the real network, but for
each server, you can specify static NAT with port translation rules that use the same mapped IP address,
but different ports. For details on how to configure this example, see
SMTP (Static NAT-with-Port-Translation), page
Cisco ASA Series Firewall CLI Configuration Guide
9-28
Typical Static NAT with Port Translation Scenario
Security
Appliance
10.1.1.1:23
Inside Outside
209.165.201.1:23
209.165.201.2:80
10-5.
Chapter 9
Network Address Translation (NAT)
Single Address for FTP, HTTP, and

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents