Get the App
SLTechnology News&Howtos  ›  Network Security  › 

DNS Doctoring NAT NAT-Hairping

Shulou Source: shulou.com Published: 2022-06-01 06:43:14 10月05日 Update

The main goal of this LAB is that the private address under the firewall can PING its own public network address.

This will be used on some special occasions. When the packet reaches the firewall, the firewall sees the public network address of the machine, and then U turns a corner and goes back to the machine.

Private address: 192.168.1.100

Public network address: 10.10.10.2

Linux (192.168.1.100)-inside (192.168.1.1)-outside (10.10.10.1)-R10 (10.10.10.10)

Router R10-10.10.10.10 (DNS server)

Ip dns server

Ip host test1 10.10.10.2

Ip host test2 10.10.10.2

Ip host test3 10.10.10.2

ASA

Object network LAN

Subnet 192.168.1.0 255.255.255.0

Object network PUBLIC <-Public network address 10.2

Host 10.10.10.2

Object network LOCAL

Host 192.168.1.100

GigabitEthernet0/0 outside 10.10.10.1 255.255.255.0 manual

GigabitEthernet0/1 inside 192.168.1.1 255.255.255.0 manual

Ciscoasa# sh run nat

Nat (inside,inside) source dynamic LAN interface destination static PUBLIC LOCAL

Nat (inside,outside) source static 192.168.1.100 10.10.10.2

Nat (inside,outside) source static 192.168.1.101 10.10.10.3

Ciscoasa# sh run same-security-traffic

Same-security-traffic permit intra-interface

Tags: Address public network firewall fire prevention machine private special occasion that is data target Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Tech Info Huawei Apple Docker MariaDB