Cisco ASA 5505 User Manual

Page 633

Advertising
background image

31-27

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 31 Configuring Twice NAT

Configuration Examples for Twice NAT

hostname(config-network-object)# host 209.165.202.129

Step 4

Add a service object for Telnet:

hostname(config)# object service TelnetObj

hostname(config-network-object)# service tcp destination eq telnet

Step 5

Configure the first twice NAT rule:

hostname(config)# nat (inside,outside) source dynamic myInsideNetwork PATaddress1

destination static TelnetWebServer TelnetWebServer service TelnetObj TelnetObj

Because you do not want to translate the destination address or port, you need to configure identity NAT
for them by specifying the same address for the real and mapped destination addresses, and the same
port for the real and mapped service.

By default, the NAT rule is added to the end of section 1 of the NAT table, See the

“Configuring Dynamic

PAT (Hide)” section on page 31-8

for more information about specifying the section and line number for

the NAT rule.

Step 6

Add a network object for the PAT address when using HTTP:

hostname(config)# object network PATaddress2

hostname(config-network-object)# host 209.165.202.130

Step 7

Add a service object for HTTP:

hostname(config)# object service HTTPObj

hostname(config-network-object)# service tcp destination eq http

Step 8

Configure the second twice NAT rule:

hostname(config)# nat (inside,outside) source dynamic myInsideNetwork PATaddress2

destination static TelnetWebServer TelnetWebServer service HTTPObj HTTPObj

Advertising