ASA Firewall nat configuration
1. Dynamic nat configuration on the firewall
Nat (inside) id No. 192.168.20.0 255.255.255.0 / / announces the network segment to be converted / /
Global (outsie) id No. 12.0.0.2-12.0.0.6 / / declare the converted network segment / /
Check that nat is show xlate deatil
two。 Dynamic pat configuration on the firewall
Nat (inside) id number 192.168.20.0 255.255.255.0 / / announces the network segment to be converted / /
Global (outside) id number 20.0.0.1 / / conversion length 20.0.01max /
3. Static nat configuration on the firewall
Static nat configuration
Static (inside,outside) 20.0.0.2 192.168.100.100 / / 20.0.0.2 corresponds to the network segment of the public network / /
Access-list abc permit ip host 20.0.0.1 host 20.0.0.2 / / configure acl to enable the network segment of the public network to access the mapped 20.0.0.2 network segment / /
Access-group abc in int outside / / apply acl to the interface / /
4. Static pat configuration on the firewall
Nat (inside) id number 192.168.20.0 255.255.255.0 / / announces the network segment to be converted / /
Global (outside) id number interface
5.nat exemption
Nat control / / starts nat conversion. If the network segment of the host in the inside area does not have nat rules, outbound / / is not allowed.
Nat (inside) id 0 0 / / convert all the network segments in the inside area to nat / /
Access-list nonat permit ip host 192.168.100.100 host 20.0.0.1 / / allows the internal network segment to access the external network segment / /
Nat (inside) 0 access-list nonat / / nonat is the name / /