1:1 NAT configuration

Reply
khomer
L0 Member

1:1 NAT configuration

Hello,

I'm having issues with 1:1 NAT set up. Using a pair of PA-5220s in Active/Passive set up. I need to set up temporary access to some devices behind the firewall. I have a block of IPs I can use. Do I need to set an IP from that block on an interface? The block I have is being routed to the primary IP of the firewall right now. What I'm trying to accomplish is:

 

Public IP-1> 10.9.20.143 (with 5 ports)

Public IP-2> 10.9.20.144 (with same 5 ports)

public IP-3> 10.9.20.155 (only one port)

 

Then would I need a separate rule for each NAT policy?

Tags (1)
SutareMayur
L6 Presenter

@khomer,

 

As per my understanding, you want to allow access to the devices using public IPs on specific ports which are behind the firewall. So yes whatever public IPs you want to use under Destination NAT, those IPs should be routable through the circuit terminated on the firewall where the request will come. Yes, most of the time it would be from the block which is configured on the interface.

 

Below NAT use cases given, you need to configure Destination static NAT. You need to have dedicated security policy and NAT for each public IP with specific ports. You can have common security policy for the public IPs which need to be allow on the same ports and the zones. But for NAT yes, there should be separate  NAT-Policy for each translation.

 

Also I would like to add here, as you’re giving access to your devices over public network, better make it available to specific source IP addresses only if possible.

 

Hope it helps!

Mayur S.
reaper
L7 Applicator

Those IP addresses do not need to be assigned to an interface as the firewall is capable of performing proxy-ARP for any destination IP in a NAT rule that performs destination NAT

 

As a best practice you should make sure the "destination interface" is set in the NAT rule to the external interface, so the firewall knows to only broadcast proxy-ARP on that interface

Tom Piens - PANgurus.com
Like my answer? check out my book! amazon.com/dp/1789956374
Katrinel
L0 Member

I just released the ultimate Cisco ASA NAT configuration guide -- 100% free, no sign up, no paywall, no mandatory e-mail subscription, no nothing =).

The article is incredibly thorough and covers pretty much everything you would need to know to really understand how to configure Auto NAT or Manual NAT to accommodate just about any address translation scenario imaginable.

Tags (1)
ximatan
L0 Member

Thanks to the increasing dependence on technology, 192.168.l.254 have become an inseparable part of everybody’s lives. A router is a device that helps people connect to the internet. There is a unique number called the IP address that helps to identify routers.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!