Where to go next – Cisco ASA 5505 User Manual

Page 581

Advertising
background image

29-27

Cisco ASA 5500 Series Configuration Guide using the CLI

Chapter 29 Information About NAT

Where to Go Next

Figure 29-24

shows a web server and DNS server on the outside. The ASA has a static translation for

the outside server. In this case, when an inside user requests the address for ftp.cisco.com from the DNS
server, the DNS server responds with the real address, 209.165.20.10. Because you want inside users to
use the mapped address for ftp.cisco.com (10.1.2.56) you need to configure DNS reply modification for
the static translation.

Figure 29-24

DNS Reply Modification, DNS Server on Host Network

Where to Go Next

To configure network object NAT, see

Chapter 30, “Configuring Network Object NAT.”

To configure twice NAT, see

Chapter 31, “Configuring Twice NAT.”

ftp.cisco.com

209.165.201.10

DNS Server

Outside

Inside

User

10.1.2.27

Static Translation on Inside to:

10.1.2.56

130022

1

2

7

6

5

4

3

DNS Query

ftp.cisco.com?

DNS Reply

209.165.201.10

DNS Reply Modification

209.165.201.10

10.1.2.56

DNS Reply

10.1.2.56

FTP Request

209.165.201.10

Dest Addr. Translation

209.165.201.10

10.1.2.56

FTP Request

10.1.2.56

Security

Appliance

Advertising