DNS Doctoring NAT NAT-Hairping
The main goal of this LAB is that the private address under the firewall can PING its own public network address.
This will be used on some special occasions. When the packet reaches the firewall, the firewall sees the public network address of the machine, and then U turns a corner and goes back to the machine.
Private address: 192.168.1.100
Public network address: 10.10.10.2
Linux (192.168.1.100)-inside (192.168.1.1)-outside (10.10.10.1)-R10 (10.10.10.10)
Router R10-10.10.10.10 (DNS server)
Ip dns server
Ip host test1 10.10.10.2
Ip host test2 10.10.10.2
Ip host test3 10.10.10.2
ASA
Object network LAN
Subnet 192.168.1.0 255.255.255.0
Object network PUBLIC <-Public network address 10.2
Host 10.10.10.2
Object network LOCAL
Host 192.168.1.100
GigabitEthernet0/0 outside 10.10.10.1 255.255.255.0 manual
GigabitEthernet0/1 inside 192.168.1.1 255.255.255.0 manual
Ciscoasa# sh run nat
Nat (inside,inside) source dynamic LAN interface destination static PUBLIC LOCAL
Nat (inside,outside) source static 192.168.1.100 10.10.10.2
Nat (inside,outside) source static 192.168.1.101 10.10.10.3
Ciscoasa# sh run same-security-traffic
Same-security-traffic permit intra-interface